I think Catalina 10.15.4 broke SSH
feed.tyler.io
feed.tyler.io
Their 10.15.4 macOS built-in ssh terminal command is unable to reach hostnames when a port number higher than 8192 is used.
EDIT:
Comments differ; one indicates issues SSH'ing to lower than 8192 ports, another indicates no issues SSH'ing to higher than 8192 ports.
This complain and Remote Access in (so I can SSH to my $4k MacBook) disables itself anytime the computer is restarted.
But more importantly, I’ve still not found a Thunderbolt Display that doesn’t routinely crash screen manager services upon idle user activity. 3 x $300 thunderbolt3 dock solutions later and not a one hasn’t crashed this computer. All main brands, two of which sell accessories in the Apple store.
Problem also existed with a top of the line 13” MacBook Pro.
I’ve just gotten used to the shoddy-ness that is Catalina. Figure if I go to the bathroom, upon return I have a fresh, new clean desktop environment. Feature not a bug. Yay!
Eventually every new release has stabilised, but it seems that doesn't hold true for Catalina.
https://www.macworld.com/article/3447396/how-to-stop-getting...
It does not prevent the red notification dot on the System Preferences app, but it does mean at least you don't get the notifications pop up on your screen.
The display is fine but it won't charge at the same time.
I have not installed the Dell 'driver'; it loads a kext so probably won't work anyway. I'm not upset about that. Docking should not require a kernel module.
That's about it. Catalina has been fine every other way.
https://www.dell.com/en-us/work/shop/accessories/apd/210-arc...
[1]: https://old.reddit.com/r/UsbCHardware/comments/ettgrg/dell_r...
The one you linked to looks like a simple wrapper of caffeinate(8).
Edit: guessing that downvoters haven't encountered a lot of people suffering from addiction
Amphetamines have legitimate therapeutic uses, it's not only crippling addiction.
I'm holding off installing Catalina on my main machine. And now they seem to focus on 10.16 instead.
I am still on Mojave tho, so may suck on Catalina.
My "fix" was to go HDMI to USB-C (instead of Thunderbold to USB-C).
I understand this might not be viable for everyone, but it resolved the issue for me.
I've been using a Dell U2515H for almost six years on my late 2013-model MBP and thunderbolt port, never had an issue. I'm also going through a Henge thunderbolt dock. It's not a macOS problem.
The monitor you have didn't properly implement the Thunderbolt spec, and since Windows has looser adherence to the spec than macOS, things work fine.
This happens with web browsers every decade or so. "Browser X" follows the Javascript spec to a tee, which breaks millions of poorly written websites, so "Browser X" has to degrade its performance or lose market share, and thus we have lots of sites that are out of spec.
Make sense?
I've tried every T3 dock available. They all have bugs that render them unusable for me. The one that was the closest to being good -- OWC 12 port I think -- wouldn't tolerate MBP sleep. After wake from overnite sleep (maybe the Mac would go to hibernate -- I didn't investigate further) the dock would need to be reset. I've never had the MPB crash though, but I haven't gone back to trying docks now with Catalina.
There certainly is something particular to your environment causing this crash. Such a bug would be in all the news.
I've found IPv6 stops working after sleep, the appropriate area in the network pane is blank (I use RA not DHCPv6). Since the Mac updates its DNS records and puts IPv6 addresses in I've found accessing via hostname stops working, but then of course I can use the IPv4 address which works fine.
In his screenshot the bad login hangs at "Connecting to clickontyler.com port" (noting that no port number appears and no period at the end).
While I can’t be sure exactly which "ssh" patch Apple may have, this seems to be the relevant file and logging code (starting at line 448):
https://github.com/openssh/openssh-portable/blob/master/sshc...
In that code, the only thing that can set the "strport" value that is used in the log is a call to getnameinfo().
If that string is corrupted in any way, e.g. not terminated or perhaps has invisible characters that trigger bad terminal behavior (such as invisibility), the act of logging it might produce the apparent hang seen here.
Again, a guess but it is possible that getnameinfo() is not necessarily processing the record correctly (for whatever reason). One such example is in the "getnameinfo" man page at the end, under CAVEATS, where they show an example of not simply trusting the result of the first call.
I don't know if Mac OS is different but on other unices ports above 1024 are not privileged, meaning that anybody can bind them. Now it increases the attack surface only a tiny bit (you have to have your sshd offline, and the attacker have local access, and them bind a fake sshd to your port in order to MitM. And even then they won't be able to spoof the server key unless it's not chmoded correctly).
Still, better safe than sorry IMO, I also use a non-standard sshd port but I keep it in the low range. In my experience it's more than sufficient to get rid of 99% of dumb attacks that generally don't bother looking beyond port 22.
My personal suggestion though is to use 1022 because it's below 1024. This means only root is allowed to bind to it. Preventing possible connection jacking attacks if an attacker is able to crash your own server and run theirs to harvest your passwords.
> So, I tried ssh ip-address -pXXXXXXXXX
This is related to the thing where what customers want most is bug fixes for existing bugs but what marketing wants most is new features to sell to new customers and marketing tends to win, which causes the number of bugs to go up rather than down over time.
I know my hardware has the ability to change my entire MAC address - I don't get why they are doing this.
The leading octets in MAC addresses are often called "vendor prefixes", and are assigned to various hardware vendors. Apple probably wants to ensure that all their devices show up in ARP scans and MAC lookups as Apple devices.
There are decent build PC laptops but you have to run Windows or Linux on them. Windows is a dumpster fire these days with ads in the start menu, the use of "dark patterns" to herd people into MS cloud, and out of control unnecessary telemetry. Linux is fine only if you have a lot of time on your hands to troubleshoot edge case issues and hunt for drivers. Linux also still (through no fault of its own) can't run a lot of apps that many people need.
What's wrong with 4k monitors? I'm typing this on Fedora machine with one (default install with no tinkering, Gnome on Wayland).
I do kind of like MacOS, but am concerned about their lack of strong interest in it.
I would pay for a "vertically integrated" open hardware Linux laptop. I've seen some promising projects but none are mature enough.
The second issue is apps, but that can be mitigated by having a Windows VM.
I would argue that any major Linux distro at this point "just work" just as well as MacOS
Then I'm having issues with PTP from my phone. Windows is fine but Plasma is broken. The phone also offers an MTP mode which thankfully works.
When I bought a Lenovo netbook in 2015, I was unable to set the screen brightness. It took a few years but eventually the issue got fixed with a new version of Kubuntu.
On my brand new ThinkPad T495 I'm having an issue with the graphics drivers, which crash and require me to issue an ACPI reboot when I close the lid and reopen it again. Pretty sure it's this issue as the error messages, symptoms and working workarounds all match. https://gitlab.freedesktop.org/drm/amd/issues/883
Ubuntu is generally even easier since they bundle in proprietary drivers.
For those business users, it just still works. For developers it's a problem.
UNIX developers, well, support OEMs that sell BSD and GNU/Linux laptops.
Then even before Catalina, my AirPods mic seems to act odd, can hardly hear it and it messses with audio output too when listening to music, sounds like I’m listening to hold music on a telephone unless I disable the mic using a third party app. I think having a old Bluetooth chip might be the reason though since I have a older MacBook while it works great on my iPhone.
Very annoying and can't find a resolution.
I can't blame them too much. It's probably worth it.
* https://openradar.appspot.com/radar?id=4931259776106496
From that and the discussions.apple.com. post, hyperlinked elsewhere in this discussion, it appears that the >8192 condition varies according to what the hostname actually is.
The bug report is datelined 2020-04-26, interestingly. There might be a bug in the bug reporting system. (-:
No, you can type whatever date you want. The "add a new radar" screen is just a bunch of text input boxes: https://i.imgur.com/nNf457J.png
> debug1: resolve_canonicalize: hostname example.org:7999 is an unrecognised address
If instead I use `-p` or a config-file option, everything works as expected.
ssh-add -A > /dev/null
... and one default value to place in your ssh config file...
AddToKeychain Yes
... to get around this issue. It works fine after that.
(On mobile. Sorry for formatting)
# Please don't resubmit the keychain patch option. It will never be accepted.
# https://github.com/Homebrew/homebrew-dupes/pull/482#issuecomment-118994372
Sadly the homebrew-dupes repo seems to have been deleted so this comment can't be read anymore.> We are uncomfortable continually supporting a 1900+ line patch which upstream hasn't signed off on that has the potential to both compromise OpenSSH security and Keychain security. From 10.11 it will also be impossible to edit plists in /System/* without disabling rootless, which isn't a configuration we'll be intentionally supporting.
They're kinda bad at that in general :/
Homebrew wants to screw around in /usr, Macports installs itself in /opt and doesn't interfere with things in the MacOS world.
Set your PATH to have /opt/local/{bin,sbin} and everything Just Works.
OpenSSH 8.2p1 notably has support for using FIDO U2F 2FA keys to secure SSH keys, it works perfectly, as long as your server also runs 8.2p1 (only the client needs to be compiled with libFIDO2).
As for the Catalina train wreck, it's clear both hardware and software quality is on a severe downward trend at Apple, you can either rant and moan about it, or take control back by switching to Linux or BSD, which is what I am doing, very slowly and deliberately.
Since you crossed that line, do yourself a favour and check out nixpkg.
I'm not sure what's the current state, but there are features on SSH I wasn't able to use due to the version provided being old.
I know that `Include` on `config` is/was one.
Include "some/path"
This is something I use frequently that wasn't available on previous built in versions.> I know that `Include` on `config` is/was one.
That's both terribly out of date info and hardly ever true as far as I can tell.
The Include directive was a new feature of OpenSSH 7.3, released on 2016-08-01.[1] Apple shipped OpenSSH 7.3 in macOS 10.12.2[2][3], released on 2016-12-13. That's a very reasonable four months gap.
I only use the system ssh because stock OpenSSH didn't integrate well with system keychain many years ago (not sure about the current state). But I've been using the Include directive for a long time.
[1] https://www.openssh.com/txt/release-7.3
[2] https://opensource.apple.com/release/macos-10122.html
[3] https://opensource.apple.com/source/OpenSSH/OpenSSH-209.30.4...
The good testers all tend to fall into what Bruce Schneier calls the 'Security Mindset' way of thinking: https://www.schneier.com/blog/archives/2008/03/the_security_...
Yeah, but surely macOS devs are eating their own dog food.
"Inside Apple they don't suffer the same problems as external users and developers."
— https://twitter.com/lapcatsoftware/status/121929275891082854...
I use alternative port but < 1023 since binding to those ports requires root. And I've never seen it being used. I'm not saying it's not, just that I did not see it in 10 years.
So it probably really is not that common.
(Granted, multi-user hosts are very rare nowadays).
(Guest in my test: OpenSSH 7.6p1 on ubuntu bionic, stock config other than sshd port.)
If you had different preferences, mostly too bad. Maybe if you reboot with system protection turned off, you can edit the config file, and hope it doesn't get reverted.
If things didn't work, like when I was getting static for audio 25% of the time I hit Play in iTunes from a shoutcast server for a whole major release, there wouldn't be any useful help on the internet. Maybe somebody had a similar problem 3 releases ago, but that fix doesn't work anymore. Other problems, or irritants are often the same way.
With Windows, most of the problems you run into are fixable, and easy to find. With an open source OS, at least you can dig in and try to fix your own problems.
This doesn't help across applications of course, and there's a reasonable argument that the inconsistency is worse than the absence -- but for me, iTerm2's FFM feature helps.
You just mean that hover over a lower window allows scrolling right? MacOS has that.
https://en.wikipedia.org/wiki/Focus_(computing)#Focus_follow...
I use Amethyst which is much easier to setup than my old Linux WMs. There are also tools like Yabai which are more customizable.
I recently made the transition (from ~10yrs Linux) to Mac and it was really smooth. At the end of the day it's just a Unix system with a really nice looking Window Manager and lots of supported apps. If you don't like the included version of SSH, just use a different one, same as linux.
EDIT: Thanks to everyone who answered my question! It makes sense to me now why one might do this.
Other possible reason is NAT. If you've got several machines or VMs but only one public IP you can port forward different public ports to port 22 on different machines. Not the only solution by a long way but a relatively straightforward one.
Of course, there are plenty of privileged ports to choose from.
https://www.google.com/search?q=random+number+between+1+and+...
Given 2 boxes with the exact same SSH setup (key auth, fail2ban, or whatever else you use) I'd prefer to admin the one with a non-standard port solely for the fact that it's not undergoing constant attack which uses resources (albeit tiny).
Testing something that uses ssh, but the test host already has a sshd running on port 22, and one does not want to disrupt that setup for the test. Or running tests as a local, non admin, user and one does not want to bother the admin with modifying the system sshd setup for those tests.
Other reasons:
Those doing it /instead/ of running on port 22 are usually doing it for one of at least two reasons:
1) a false sense of security. If you do an internet search, you'll find plenty of blog posts boasting that using an alternate port is a security feature (it is not, it is security via obscurity); or
2) to reduce the log growth from all the script kiddie scans that target port 22 (note, no security is added here, but one's log files don't grow quite as rapidly either).
The only hosts we have with any SSH exposed to the world at all are a couple of bastion hosts. Day-to-day we access everything else through a VPN, so its only exposed at all as an emergency backup in case the VPN breaks. Really no inconvenience to having it moved to a high port.
Security-wise, it seems pointless; my daemons on random non-standard ports still get hammered, and fail2ban takes care of keeping the log spam down just as easily as it does the ones on 22.
I have my publicly-accessible SSH port on not-22, just to avoid the log messages from scanners. I'm well aware it does not, on its own, actually "secure" anything, but it brings more convenience to me for it to be a bit obscure, and it certainly isn't hurting anything.
Thank you about that clarification. Also your website seems to be down actually.
+1
My Mac's resources were getting gobbled up by an internal process I coudln't terminate and my keychain was borked and I couldn't log in after a reset (to try and get around the resource hogging). Recovery didn't get me any where so I used Recovery over the Internet to do a clean install.
I'm running 10.15.4, no issues as of yet. And this all occurred after the security update. I'm running on the version prior for now but will make sure I've got a good backup and give it another go.
sudo softwareupdate --ignore "macOS Catalina"
defaults write com.apple.systempreferences AttentionPrefBundleIDs 0
killall Dock
Apple should really slow down on major releases of macOS or stop altogether in my opinion. macOS Mojave is a great OS and it's basically feature complete. Just stick with that, introduce bug fixes and security patches as needed and I think people will be happy.Is that a common thing to do, or any reason why the OP would do that? Doesn't ssh reject your key, saying it does that if there's such a problem? And even if not wouldn't it be advisable to at least look at the permissions; I mean suppose they're not -rw------- or so, wouldn't you want to know that, and also why they are not ok?
One might uncharitably suggest that using macOS and expecting standard decades-old Unix behaviour is itself bizarre … but that's also true of using Linux with systemd (viz., nohup no longer nohups, or systemd-resolved, or innumerable other broken bits).
It's almost as though no-one cares about quality anymore.
However, there is an amazingly easy workaround, assuming the IP and port don’t change often: create a ~/bin shell script that connects via IP and port, make it executable, and add ~/bin to PATH.
This workaround doesn’t excuse Apple of doing something so egregiously stupid, but it’s so easy that you may as well do it and move on.
I tested this specifically on a number of servers that I run with port numbers > 10000, using /usr/bin/ssh on macOS 10.15.4, with and without IP addresses. Nothing broke for me.
Still not sure if that is my machine, or a general fault - but the lack of monitor and promiscuous mode is playing havoc with IPv6 multicast packets from VMware Fusion VMs.
I love having the Linux kernel with a nice UI but there are some useful commands that are missing.
There are ways to get them set up but in any case it’s kind of a pain
Have had no issues with it at all.
Whoops
Someone should have paid more attention to that verbose SSH output first.
'ssh -4 <hostname>'
The issue with them is lack of testing before deploying them.
Welp.
(I'm about 80% kidding but amused. Lockdown.)
That's my intent. I'll put it back online for others to find once the fuss dies down.
One important thing to always remember is that unless someone posted their article to Hacker News themselves they might have had absolutely no expectation that a huge audience was about to descend and dissect everything they wrote. They might have just been talking off the cuff, mentally noodling around or even just using the process of writing stuff down as a means to sort their thoughts. Far too often HN commenters work from the assumption that an author is intending to make A Big Point and very uncharitably deconstruct every sentence the author wrote.
It's only a matter of time before we see a reply along the lines of "OBVIOUSLY 10.15.4 did NOT break SSH, the author just didn't do X Y and Z to fix a very OBVIOUS mistake in their SSH config".
> Why would you take down the post as it’s probably useful to others?
More broadly, Tyler doesn't owe the world anything in this regard. If he wants to post it, cool. If he wants to remove it, cool.
dang, join in if you must.
Ends up on Hacker News again bitching about Catalina.
Paying taxes anyway
> I’m not even going to go into it. I don’t want to end up on Hacker News again bitching about Catalina. I just hope I’ve stuffed this post with enough keywords so that anyone else searching on Google might come across the answer.
Shocking!
Granted high ports shouldn't be broken, but running SSH on a non-standard port is security (read obscurity) theater at best.
There's really not much benefit, unless you need multiple sshds on the same IP, but at that point I'd question the sanity of the approach.
Here’s another example. Say you have a web server running that is only for internal employee use. But you want to expose it externally so that they can reach it without a VPN. Even if you follow proper security protocols, why would you not turn off search engine indexing on this page, and limit the pages that link to it? It will not increase the inherent security of the protocol or the user accounts, but it will drastically lower the # of bots using up CPU and iptables entries trying to fail2ban or blacklist them.
Security is a spectrum and you want to have defense in depth. Moving ssh to a nonstandard port is a security best practice and you shouldn’t be advising people not to use it. But should they also have good key setting, fail2ban, ip whitelisting/blacklisting, etc? Of course they should.
For whom? Could you please cite this?