OpenSSH 10.6

(openssh.org)

78 points by torcete3 hours ago

7 comments

  • davb1 hour ago
    I found a small bug in QoS handling in the OpenSSH client under specific conditions. It had a big impact on my workflow but wasn’t a complete showstopper and might not have had an obvious impact on the broader user base. I raised an issue on the tracker and within a day I had a test build, a confirmed fix and a note of which release would carry the fix. It was one of the most positive experiences I’ve had reporting a bug, especially for a non-security issue.<p>I know this comment doesn’t add much to the conversation about this release, but I’m very grateful to Damien (who handled the issue) and the team for the wonderful job they’re doing on such a core piece of software.
    • tiffanyh1 hour ago
      &gt; I raised an issue on the tracker<p>I thought OpenBSD &#x2F; OpenSSH operate without a tracker and it’s all email distro based.
      • throw0101a49 minutes ago
        OpenSSH uses Bugzilla:<p>* <a href="https:&#x2F;&#x2F;www.openssh.org&#x2F;report.html" rel="nofollow">https:&#x2F;&#x2F;www.openssh.org&#x2F;report.html</a>
    • kuekacang1 hour ago
      Link or didn&#x27;t hapen &#x2F;s<p>But seriously if feasible, share the issue link. Especially when there&#x27;s conversation involved, it&#x27;s different kind of nice (and learning opportunity) reading such thread
  • brynet2 hours ago
    &gt; sshd(8): On OS X SDK &gt;= 27, sandboxing is no longer supported as the API we depended upon has been removed and no obvious alternative provided.<p><a href="https:&#x2F;&#x2F;github.com&#x2F;openssh&#x2F;openssh-portable&#x2F;commit&#x2F;d4b4c304a202f5099f2f60be9af9ba266212bb74" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;openssh&#x2F;openssh-portable&#x2F;commit&#x2F;d4b4c304a...</a>
    • mrpippy1 hour ago
      I look forward to seeing if Apple makes any changes in the fork they ship with the OS: <a href="https:&#x2F;&#x2F;github.com&#x2F;apple-oss-distributions&#x2F;OpenSSH" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;apple-oss-distributions&#x2F;OpenSSH</a>.<p>&quot;Updated sandbox for privilege-separated pre-authorization sshd process&quot; is listed as a modification to the open-source project, but I suspect this is out-of-date.
    • kccqzy2 hours ago
      Deprecated since Mountain Lion. <a href="https:&#x2F;&#x2F;issuetracker.google.com&#x2F;40474030" rel="nofollow">https:&#x2F;&#x2F;issuetracker.google.com&#x2F;40474030</a><p>It’s what Apple experimented with before they came up with the current entitlements system.
      • djmdjm5 minutes ago
        Entitlements are a great system for user applications, but pretty much unusable for OSS system applications as AIUI they need codesigned binaries
  • FloatArtifact3 hours ago
    &quot; * We have seen a number of cases where a security bug identified * by AI tools is subsequently independently discovered by a * different researcher. This suggests that adversaries who do not * report bugs to OSS projects are likely to be able to discover * these bugs too. Given this, the OpenSSH team will, for now, be * making more frequent releases to get bugfixes into users&#x27; hands * more quickly rather than batching them until the next planned * release.&quot;
  • tptacek1 hour ago
    The big ticket thing here seems to be mitigation of &quot;Crossing The Streams&quot;, a CRIME-style compression side channel that relies on the fact that different sessions share LZ77 state:<p><a href="https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;2609.07709" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;2609.07709</a>
  • ilaksh2 hours ago
    They mention a donation link: <a href="https:&#x2F;&#x2F;www.openbsd.org&#x2F;donations.html" rel="nofollow">https:&#x2F;&#x2F;www.openbsd.org&#x2F;donations.html</a><p>I wonder what their funding is like.
  • po1nt2 hours ago
    I think this is much healthier approach to AI reports than curl has. But I understand both sides.
    • this_user1 hour ago
      OpenSSH don&#x27;t have the same luxury of being able to ignore potential vulnerabilities.
      • mitxela56 minutes ago
        Curl doesn&#x27;t ignore vulnerabilities
  • robinpie2 hours ago
    Really glad to see the rate of security fixes speeding up.