9 ms·
Mosh: the mobile shell
- visarga 10y agoOh, it's just a repost. I thought they released version 1.3 with scrollback support.
- ajdlinux 10y agoThe lack of scrollback support has made mosh pretty useless to me. I like many of its other features, but in order for it to replace ssh for me it needs to look like it's just printing text to stdout. (Yes, this is why I also tend to avoid using screen and tmux for anything other than holding open a remote shell session.) Will have to check out 1.3...
- crest 10y agomosh $REMOTE -- tmux new -ADs $SESSION
- shocks 10y agoA great bit of kit, but totally unusable for me because of a lack of agent fowarding support[1]. :( 1: https://github.com/mobile-shell/mosh/issues/120 https://github.com/mobile-shell/mosh/issues/120
- d33 10y agoWhy would you need agent forwarding? It's a really dangerous feature.
- jstanley 10y agoIt's useful in a corporate environment where you have tens to hundreds of machines you need to use, and all of them are trusted. EDIT: "a really dangerous feature" is accurate though. For example if all of the staff have root access on a staging machine, then anybody can steal the ssh-agent of another user on the staging machine, and use it to login as that user on production machines.
- ajdlinux 10y agoIt'd be kinda nice if you could wrap it with some minimal level of protection through SELinux or something. Still wouldn't be as secure as switching it off, but at least a malicious insider would have to jump through a couple of hoops to get there.
- Daviey 10y agoA better way of solving it is to resolve the issue i raised: https://github.com/mobile-shell/mosh/issues/285 https://github.com/mobile-shell/mosh/issues/285
- 4ad 10y agoIn such an environment you should be using Kerberos. Then you won't need agent forwarding, and you can maintain security. I would argue that in such an environment you really should be using LDAP+Kerberos, but if you think LDAP is too much effort (it really isn't), plain Kerberos is comparatively trivial to administer, and adding Kerberos (unlike LDAP) doesn't really require any significant changes to your environment.
- brians 10y agoWhy is Kerberos ticket forwarding better than agent forwarding? Either way, root (or a bad .bashrc) can use your credentials while you're logged in.
- 4ad 10y agoSorry. You are absolutely right. Long day... I disable Kerberos ticket forwarding here, for this exact same reason. But then you don't have ticket forwarding! I don't know what I was thinking.
- jstanley 10y agoHow does LDAP solve the problem? We use LDAP to manage public keys for each user, but they still need to supply a private key at some point.
- ajdlinux 10y agoExtraordinarily useful on an internal corporate network, especially when you're scp'ing remote->remote and so on.
- 4ad 10y agoJust use kerberos. You don't need LDAP to use Kerberos (although you probably should be using LDAP too). Kerberos without LDAP is trivial to set-up and administer, and it's very non-invasive, so you don't need to do any significant changes to your organization.
- vacri 10y agossh'ing through the jumphost when the VPN on it wasn't working properly was a use-case for me. Agent forwarding is fine, as long as you use it judiciously.
- Mic92 10y agoI use this patch for some time and it works great for me.
- donatj 10y agoAs I recall it needs a swath of nearly a thousand ports open. Getting one opened in a corporate environment is difficult enough.
- sschueller 10y agodepends on number of connections, 60000-60020 works fine.
- d33 10y agoThat's a weird setup! Why wouldn't they use a single port?
- deleted 10y ago[deleted]
- homero 10y agoBunch of udp
- fungi 10y agoMakes managing a cheap European vps from Australia bearable.
- sschueller 10y agoWhile on a train going through a tunnel :) At least that is what I use it for in Switzerland :)
- LeonidasXIV 10y agoNo internet in swiss tunnels? I'm a bit disappointed now.
- exDM69 10y agoIt's amazing how well mosh can keep connections alive through network outages. I have unbearably unreliable mobile network connection and plain old SSH connections drop regularly but Mosh just keeps on going. And it doesn't require me to reconnect when I enable/disable my work VPN.
- justinsaccount 10y ago> It's amazing how well mosh can keep connections alive through network outages It doesn't. It uses udp, there is no connection to keep alive. > And it doesn't require me to reconnect when I enable/disable my work VPN. That's why this works.
- okket 10y agoTesting mosh made me aware how much I am relying on the port forwarding feature in ssh in my daily work, and how hard it is to replace it. Otherwise: Great tool.
- andrewl-hn 10y agoI would really love to see an adapter layer on top of Mosh, so that it can be a drop-in replacement for an SSH client. Currently even after you install it on your servers you have to change your scripts and learn new CLI options. I know that there are reasons for these differences, but inability to alias `ssh` to `mosh` or hypothetical `mosh-ssh` hurts adoption.
- StavrosK 10y agoWhat new CLI options? Mosh pretty much doesn't have any, you use SSH if you want to do what SSH does.
- PolCPP 10y agoStuff like connecting to different port, you need to do --ssh="ssh -p 1111"
- StavrosK 10y agoOh, that's because you're running SSH under the hood. I see what you mean, having the port be passed to SSH would be better from a UX standpoint, but the thing is that mosh doesn't do everything SSH does, so it would need to fake every SSH option and then pass them through. As it is, you only need to learn --ssh and you can do "--ssh=ssh -D 8223 -L 1234:localhost:1234" etc.
- insaneirish 10y agoAs a side note, Keith Winstein (https://cs.stanford.edu/~keithw/ https://cs.stanford.edu/~keithw/), the creator of mosh, is an interesting guy (e.g. he used to be a WSJ reporter among other things). I had the pleasure of seeing him speak at a conference last year on the topic of TCP congestion control algorithms. I admit, I expected it to be a boring presentation, but was then thrilled as it was one of the most dynamic, informative, and funny technical talks I've ever seen. That particular presentation isn't online, but he links to several others on similar topics. I would check them out. They're probably pretty good!
- berbc 10y agoHis presentation "Transport Architectures for an Evolving Internet" could be the one you're referring to? It's online and very interesting: https://www.youtube.com/watch?v=UsCOVF0vDe8 https://www.youtube.com/watch?v=UsCOVF0vDe8.
- pixelbeat 10y agomosh is fantastic for me when working remotely over vpn. I don't have to worry about reconnections, disconnections, packet lag (due to local echo feature). mosh in combination with screen (or tmux) gives scrollback support + other features
- seba_dos1 10y agoPrevious discussions: https://news.ycombinator.com/item?id=3819382 https://news.ycombinator.com/item?id=3819382 https://news.ycombinator.com/item?id=11572146 https://news.ycombinator.com/item?id=11572146 https://news.ycombinator.com/item?id=8928506 https://news.ycombinator.com/item?id=8928506 https://news.ycombinator.com/item?id=8252093 https://news.ycombinator.com/item?id=8252093 https://news.ycombinator.com/item?id=5016745 https://news.ycombinator.com/item?id=5016745
- cyphar 10y agoOne of the weirdest issues I've had with Mosh is when you resize a window (for example you open a new pane in tmux where you have a mosh session open). Mosh will just cut off parts of the scrollback (if you do something like return from vim). Is this a known issue, or should I file a new bug?
- tambourine_man 10y agoI really don't get HN's new dedup algorithm. https://news.ycombinator.com/item?id=12429203 https://news.ycombinator.com/item?id=12429203 https://news.ycombinator.com/item?id=5016745 https://news.ycombinator.com/item?id=5016745
- qwertyuiop924 10y agoMosh is possibly the most useful piece of software that I've seen: it makes remote links over slow, unreliable networks bearable for doing Real Work. Speaking as somebody who usually has two rubbish networks between the computer I'm on, and the conputer I'm connecting to, that's incredibly useful.
- musicmatze 10y agoAbsolutely. I'm using it for two or years or something by now and the very first thing I do when having a new host: install the mosh server.
- homero 10y agoI love it but the clients I use don't support it. Winscp and serverauditor. I didn't like juicessh on Android
- michaelmior 10y agoI personally quite like JuiceSSH. Mosh support being one of the reasons :) It's great for the odd scenario when something is down and I need to a quick fix over 3G.
- atmosx 10y agoThere was a FreeBSD bug in mosh, which led to high CPU usage which prevented me from trying it twice in the past.
- adrinavarro 10y agomosh is really good when used from a tablet device, ie. with Blink: https://twitter.com/BlinkShell https://twitter.com/BlinkShell
- abhinavk 10y agoWith Chrome apps being phased out, is a native Windows app in the pipeline?