3 ms·
OpenSSH is indeed widely used. But the only game in town they're not. There are commercial SSH implementations that aren't based on OpenSSH, reasonably widely u
by OliverJones 3y ago
OpenSSH is indeed widely used. But the only game in town they're not. There are commercial SSH implementations that aren't based on OpenSSH, reasonably widely used too. For decades I've used a Windows product called SecureCRT based on their own ssh and sshd stacks at Van Dyke. I'm sure there are others too. (I hated putty's UI.)
There's an obvious infosec observation here. Different stacks, different hacks. Maybe individual infosec people should adopt a randomly chosen stack from among the less popular. Then the dreaded zero-day that hits the most popular stack won't cut off their access entirely.
- tonyarkles 3y agoI totally forgot that the very original version of SSH came out in 1995 and turned into a commercial product. https://www.ssh.com/home-page https://www.ssh.com/home-page
- chasil 3y agoWe run it on our VAX. The article also says: "I don't think anyone else is working on new protocol features; instead, OpenSSH comes up with them and then people with other SSH implementations either follow along or not." One obvious exception is curve25519-sha256@libssh.org which is the preferred kex.
- firstlink 3y agoTo this day I occasionally attempt to run `emerge ssh` to update it and get back portage's version of "I can't do that, Dave". Then, "oh, right..." `emerge openssh`.
- mardifoufs 3y agoI'm curious to know what are the advantages of using those other implementations instead of OpenSSH. Was it mostly because Windows didn't have openssh? Or do they provide more features (or less! which could be good for security)? I have only ever used OpenSSH so I'm totally ignorant about everything else!
- OliverJones 3y agoI went with SecureCRT because it had its own well-done terminal emulator back in the mid-1990s when I started using it. It's evolved nicely ever since.
- hsbauauvhabzb 3y agoCase studies of OpenSSH vulnerabilities are fairly limited, iirc there are a few ssh engines with fairly frequent issues. Safety in numbers is probably a better option than security through obscurity in this case.