Detecting SSH Tunnels (2017)
trisul.org
trisul.org
The Great Firewall certainly can detect and block SSH too, but there are ways around that as discussed at https://news.ycombinator.com/item?id=36531485
intersecting sets.
On some external system you just setup stunnel/socat/haproxy to listen on port 443 with TLS and proxy to TCP port 22, then just use openssh with openssl s_client as the proxy command.
So if that's your concern, perhaps address the communication, not the ssh tunnel.
I appreciate that SSH can be obsfucated via an SSL tunnel but the article didn't come at that angle.
The article itself even states: >with SSH everything goes dark right after the initial capabilities exchange.
So... What say about before the exchange?
It could be a 4-line bash alias, any SSH activity that doesn't go through your wrapper could be considered suspicious
The plebs can't be trusted to respect our wealth and superiority.
/s
See e.g. https://linux.die.net/man/1/ssh section "Escape Characters" and "~C' Open command line. Currently this allows the addition of port forwardings ..."
Of course any concerns about the vulnerabilities in their closed source implementations are handwaved away.
The future may be your actual traffic through ssh tunneled through https with esni to a server behind Cloudflare. Unless you want pseudo security tools to mess with your traffic.
The password update app will news SSL protocols and cryptography that are vastly out of date.
There will be no synchronization of passwords across various systems used in the company so you will have to memorize multiple passwords which means writing them down.
Isn't this mitigated in newer TLS versions?
It's a separate addition. Chrome has already started their gradual rollout of ECH (previously known as ESNI). Though I haven't seen nice server-side implementations/automation.