20 ms·
Dropbear SSH, a lightweight alternative to OpenSSH
- mehrdadn 8y agoI recall I've had trouble finding good documentation on the equivalent of OpenSSH features in Dropbear. Stuff like restricting the client IP or disabling port forwarding... lesser-used features like these. It's been a while though.
- gelstudios 8y agoThe general pattern used by most of these "lightweight" implementations of system software is granular compile-time options for every additional bit of functionality. https://busybox.net https://busybox.net is a good example of this.
- burnte 8y agoVery common in embedded devices. This link isn't working at the moment, so here's a link to the actual project: https://matt.ucc.asn.au/dropbear/dropbear.html https://matt.ucc.asn.au/dropbear/dropbear.html
- hrnnnnnn 8y agoI followed that literarary-clock kindle tutorial at the weekend, and I think dropbear was the SSH client the networking hack used. Makes sense if it's designed to be low-resource.
- jacob019 8y agoOften used with ARM, why is it never used by default on X86/X64 distros? I would think that the "lightweight" alternative would be lean and mean, kind of like Nginx vs Apache.
- chasil 8y agoIt doesn't do privilege separation and it's had a few security issues (like CVE-2016-7409). I also think that some of the more exotic features are missing. https://matt.ucc.asn.au/dropbear/CHANGES https://matt.ucc.asn.au/dropbear/CHANGES
- ajross 8y agoNginx won because it was faster, simpler and more easily extended, not because it was "lightweight" per se. In comparison, dropbear doesn't really do anything that ssh doesn't, and lags in a bunch of esoteric features that "most" people don't use but that inevitably some people do. Who wants to use a distro where one's preferred ssh-agent feature or X11 forwarding inexplicably doesn't work? Dropbear is small and builds cleanly everywhere, so it's what you pick if you're size constrained or just need "an ssh" for your embedded environment and don't want to bother integrating something larger. No one specifically wants it at the command line on their "Linux" system.
- mkj 8y agoDropbear author here. It used to have one unique feature, but OpenSSH has copied it now[0] :) dbclient host1,host2,user@host3 to onion-TCP-forward through a few hosts. [0] https://manpages.debian.org/stretch/openssh-client/ssh.1.en.html#J_10 https://manpages.debian.org/stretch/openssh-client/ssh.1.en....
- chris_wot 8y agoSo... are you an Australian? Only Australians know how deadly dropbears are.
- Alupis 8y agoJust want to say thanks for your work! When I was elbow-deep in CLFS[1], I never ran into trouble getting Dropbear to compile and work with my fledgling Linux Distro, and upon reflection that is quite an accomplishment and something I'm thankful for. Dropbear "just worked", and it worked well. It was the first "portal" into my Distro, and I can still remember SSH'ing into my system for the first time and being completely amazed it worked at all, let alone returned a shell prompt! Open Source projects don't get enough appreciation, and our Open Source hero's, such as yourself, get even less. Thank you for Dropbear! [1] http://trac.clfs.org/ http://trac.clfs.org/
- fapjacks 8y agoHey! I love Dropbear for embedded! Sending you a long-distance highfive!
- jagger27 8y agoI believe Alpine Linux offers it in the installer.
- yjftsjthsd-h 8y agoNot "default" per se, but Alpine Linux gives you the pick of openssh or dropbear when you install the system, and doesn't appear to have a preference which you use. If course, Alpine is borderline embedded, so not exactly a counterpoint.
- perch56 8y agoIn a recent vulnerability assessment that I performed, I was surprised to find out that Cisco is using Dropbear on products such as UCS Managed C240M servers.
- jacobush 8y agoSo there is SSHD on ios... :-P
- tamatsyk 8y ago> Resource Limit Is Reached :\
- rl3 8y agoI use an ad-free, open-source Android app called SimpleSSHD that implements a Dropbear SSH server. Being able to SSH into your phone and wirelessly perform an incremental rsync backup of all your photos and data is life-changing compared to the hell that is cables and the MTP protocol. Thank you to all these projects for delivering me from the clutches of MTP, I am indebted.
- adrianratnapala 8y agoA long time ago, when I tried something like that, I was stymied because the SSH server did not have permissions to write to any directory which the document readers etc. could see. Is this sort of thing still a problem? How did you get around it?
- rl3 8y agoIt was never an issue for me. Giving the SimpleSSHD docs a quick glance, the app itself does not operate as root, although its packaged subcomponents like rsync optionally can depending on what shell you point them to. My phone isn't rooted. Everything in /storage/emulated/0 backs up without issue. Obviously not a full system backup, but all my data none the less. With regards to write permission, I've only ever issued any writes to my image folders to prune photos or screenshots older than xx days that have already been backed up. On that note, freeing up 20GB of space instantly with a single command is incredibly satisfying (compared to the MTP hell alternative).
- CapacitorSet 8y agoIf you only need a shell, adb does that, as well as blazing fast file transfer (for the standards of MTP).
- rl3 8y agoFor sure, although I think it isn't as well suited to being a remote daemon. With SimpleSSHD, all concerns are compartmentalized into an app, you get rsync out of the box plus a nice minimalist UI for monitoring. Then adb can be left disabled, and its configuration untouched.
- mirimir 8y agoDropbear works well for preboot LUKS unlocking with remote servers.
- arminiusreturns 8y agoThis is how I've used it as well. (Initram luks shim, I call it)
- SpaceGorilla 8y agoHuh, this sounds too good to be true. Remote FDE? Yes please!
- teddyh 8y ago(Shameless plug:) For automatic unlocking at unattended reboots of LUKS-locked remote servers, see Mandos: https://www.recompile.se/mandos https://www.recompile.se/mandos
- mirimir 8y agoYes, this is devilish clever stuff :)
- aesh2Xa1 8y agoHow's that work? Are you unlocking, say, a rootfs on boot or something entirely different? I'm curious about the use case and the method.
- loxias 8y agoCurrently, all my remote servers of any import use LUKS to encrypt the PVs. My /boot is a tiny unencrypted filesystem containing just the kernel, and an initrd, which prompts for my decryption key before booting. (afaict, the standard setup) For remote servers, I reboot them and then have to use a serial console to type in the LUKS password. Are you saying that with this, I could put an ssh server in the initrd (and I guess I'd have to make sure network was up as well), that I could log in to to provide my LUKS password???? Because that would be ... beautiful.
- fao_ 8y agoDoes this have anything to do with http://bearssl.org/ http://bearssl.org/ ?
- Tomte 8y agoNo, Bear SSL is recent, DropBear has existed for a very long time.
- blackfawn 8y agoI believe Dropbear still has limited to no SFTP support but otherwise I've been very happy with it. Dropbear is the default SSH server for DietPi[0], a lightweight image for Raspberry Pi and other (mainly single board) computers. [0] https://dietpi.com/ https://dietpi.com/
- millette 8y agoArchived: http://archive.is/9lu2S http://archive.is/9lu2S
- fulafel 8y agoCheck out the security track record before using this. There have been occasional RCE's.
- fapjacks 8y agoA word of caution: Many (most) IRC spambot detectors check if your connecting IP is also running a Dropbear SSHd service. This can cause you to be k-lined in some instances, and it's not immediately obvious to basically everyone why the anti-spambot bots are flagging your connection. Of course, this isn't Dropbear SSHd's fault. Just something you might want to keep in mind if you use both of these things.
- DownGoat 8y agoIt is because dropbear is very common in embedded systems. They are commonly riddled with vulnerabilities, so they are getting hacked almost as soon as they are publicly reachable. This is not because of dropbear, but because they are typically configured with weak credentials that are newer changed. I guess IRC servers see a lot of spam from such devices, so they just drop all systems which has dropbear.
- irundebian 8y agoIt's probably also because of dropbear since embedded devices often run old versions and dropbear seemed to be vulnerable to severe vulnerabilities in the past: https://www.cvedetails.com/vulnerability-list/vendor_id-15806/year-2017/Dropbear-Ssh-Project.html https://www.cvedetails.com/vulnerability-list/vendor_id-1580...
- mkj 8y agoHuh, what kind of dodgy IRC servers have you been on ;) ? I've never encountered that in years of IRCing from hosts running Dropbear, though I could see it happening.
- fapjacks 8y agoHeh I should be more precise. During the summer storm season (for example the attacks last week across most of the popular networks), most networks deploy spambot countermeasures that they don't typically run on a normal day. But when they flip the switch, it tests new connections only. So for example I use ZNC and essentially never disconnect. But I disconnected to renew my LetsEncrypt certs during this time and then was k-lined on reconnection on a couple of networks.
- iveqy 8y agoI needed a ssh server with some tweaks a few years ago. I must say that the dropbear code was very neatly written, easy to read and easy to understand. It made me to choose dropbear instead of openssh for my tweaks. I would have used dropbear on my main machine as well, but it doesn't seem to support ~/.ssh/config
- deleted 8y ago[deleted]
- faragon 8y agoDropbear SSH is also shipped into OpenWrt. It works great, including ssh keys, useful for ssh/scp automation.
- GTP 8y ago"resource limit reached" When publishing something on hn kills it.
- eldios 8y agoDropbear has been created in 2002. From the project ChangeLog: ``` [..] 0.28 - Sun Apr 6 2003 - Initial public release Development was started in October 2002 ``` ..why is it surfacing now on HN? O_o
- zymhan 8y agoI mean it's good to remind people of older and less-known projects, but Dropbear is quite common for embedded Linux applications. OpenWRT uses it for example.
- S-E-P 8y agoUsed Dropbear on many occasion on both iOS and Android, very quality this one
- vermaden 8y agoI only miss one option in the Dropbead, the UseDNS No equivalent from OpenSSH.
- mkj 8y agoThat should be the default in Dropbear (as a compile-time option)? #define DO_HOST_LOOKUP 0
- thom_nic 8y agoIf anyone is interested in other lightweight tools to complement a minimal embedded linux distro, check out Troglobit's GitHub repo: https://github.com/troglobit https://github.com/troglobit. He has a collection of tiny apps perfect for embedded systems, such as... - mdnsd (not in Busybox), - merecat httpd (much more full-featured than busybox httpd) - inadyn dynamic DNS updater - finit (IMO much nicer than busybox's runsv) - watchdogd - uftpd - ntpd (with ipv6 support!) He has been super responsive to requests as well.
- JoshuaRLi 8y agoThis is great, thanks for sharing!