SSF, a network tool with new features, performance and security in mind
securesocketfunneling.github.io
securesocketfunneling.github.io
About the yet-single push : the project was not initially meant to be OpenSourced. Next commits will be more frequent, with more details.
About your concerns regarding trust: that's one of the strongest motivation for developing and OpenSourcing this project. Pre-built binaries can be tested against your own build. A lot of work was done to make the build a really straightforward process. Most of the complexity of building and linking third-party libraries (e.g OpenSSL or Boost) is contained (local to the project) and automated.
By the way, SSF-Cmake scripts are really useful, and could be used by anyone, in any project.
More details : http://securesocketfunneling.github.io/ssf/#how-to-build-lin...
The cryptographic part is entirely based on OpenSSL (latest version), and depends on sources only. SSF only supports latest TLS-1.2 and default cipher suite is DHE-RSA-AES256-GCM-SHA384 (RSA based authentication, perfect forward secrecy enabled, AES 256 based symmetric cipher in Galois Counter Mode). The RSA key sizes depends on you.
More details : http://securesocketfunneling.github.io/ssf/#security-feature...
Not being famous does not necessarily means being suspicious. We are open to any suggestion regarding the project, build-system or trust issues.
But since you asked, "we" are two Belgian C++ enthusiasts happy to contribute to OpenSource community that gave us so much.
We have been working on this project for a couple of years and we are very excited to release it.
I'm not suggesting that bugs won't be fixed or there are backdoors, and this is definitely a really interesting project. However there's just very little to convince me that I should trust this project for anything more than a throw-away experiment right now.
"the project was not initially meant to be OpenSourced"
Sounds like an interesting backstory - what's the motivation to open source it so?
"Not being famous does not necessarily means being suspicious."
It's not being famous that matters here. Publishing software anonymously is unusual (I'm sure there are exceptions here, however they're definitely exceptions). Whenever I read of a new web service or software I generally dig into who is behind it and why they're doing it. Code on its own does not convince you to use it.
We are currently planning and working on new features. Right now, we are focusing on making the networking part even more modular and extendible (e.g. a transport layer based on UDP rather than TCP). Moreover, an other goal we would like to reach is to make the global framework simpler so that contributors could add to SSF their own features quickly and easily.
What is the canonical replacement to `tar czf - /some/folder | ssh user@host "tar xvf -C /some/folder -"` ?
Key management could use a bit of doc, how do you generate all these keys ? It would be nice to have a ssf-keygen tool.
Looking forward to see this gaining more traction.
I wonder if there's still any real need to support both (but perhaps v5 layers on top of v4, so it makes sense to implement them in layers, and little overhead to provide both?). They have a howto-section on manually forwarding dns - but socks5 really should be enough for most applications.
While a general forwarding tool will always be able to forward dns, from a security and usability standpoint, it would seem just providing socks5 (and 5 only) might be better.
As for piping - as I mentioned it looks like there's no support built in - but it should be possible to make a wrapper. Would need something on the other end though - like a netcat that takes an output filename, and then spawns another listener and redirects to a file or something.
I'd be interested in if there's any real performance differences between openssh socks5/forwarding and this project. Especially since they build on the same primitives.
[1] https://github.com/securesocketfunneling/ssf/tree/master/src...
For a simple comparison between SSH and SSF performances, you can take a look at the website (https://securesocketfunneling.github.io/ssf/#performances)
Thanks for digging into the code
I think the last time I tested scp (with a large media file) over gigabit ethernet, ssh managed to saturate the link. Odd if that only holds for scp. Almost sounds as if the version of openssh used didn't use hw acceleration?
There is a page on the website with a benchmark between SSF and SSH. It is a little bit basic. The test is done on TCP port forwarding.
Concerning your use case, it would be interesting to support it. We will look into it. It might not be straightforward to make it crossplatform.
Regarding the key generation, there is a tutorial on the website (https://securesocketfunneling.github.io/ssf/#security-featur...). We also have our own script to generate test keys. We can make it more user-friendly and publish it.