13 ms·
How SSH port became 22 (2017)
- justahuman74 3y agothis WKS field in DNS that it refers to isn't something I've heard about Why isn't it used?
- mzs 3y agohttps://datatracker.ietf.org/doc/html/rfc1123#page-14 https://datatracker.ietf.org/doc/html/rfc1123#page-14
- duskwuff 3y agoThe WKS record type was, at one point, a record listing all network services available on a host. It consisted of a bitmap where each bit represented a port number, counting from 0 (!), where a bit being set indicated that the host offered a service on that port. This scheme only worked for low port numbers; it also inappropriately conflated DNS names with hosts. (The latter was perhaps a reasonable assumption when WKS was created sometime in the '70s or '80s, but it certainly isn't anymore.) The most definitive references to WKS are probably: * RFC 1035 (1987), which defines the record format. * RFC 1912 (1996), which noted that "[WKS records] serve no known useful function, except internally among LISP machines. Don't use them."
- justsomehnguy 3y agoYou can do a lot better now with SRV records.
- usr1106 3y agoIn 1995 everybody sending email was trustworthy. Those were the days... Edit: Except if their address was @aol.com. Eternal September started in 1993.
- I_am_uncreative 3y agoI have a shirt that says "The Internet is full: Go Away!"
- tetris11 3y agoI will pay you 5 cents to print 15 of those t-shirts, with my company logo on it and a QR code that points to an article about an internet standard and why my crypto startup is better than it. 10 cents, final offer.
- bazil376 3y ago“Can I have port 22?” “Yes” the early days of the internet are so fantastical to me I can’t stand it. Makes me sad to be too young to have witnessed it.
- Dwedit 3y agoThe early days of the internet were dominated by InfoSeek Net Search, then later on Alta Vista was the search engine of choice. Then later on, Google appeared and everyone else couldn't compete.
- lttlrck 3y agoThat's closer to an abridged history of "World Wide Web" search engines. The internet was decades old when Infoseek appeared.
- jedrek 3y agothe internet was decades old when http appeared.
- blahyawnblah 3y agoWas it DEC than ran Alta Vista? They were involved in some search engine
- coobird 3y agoIndeed.[1] I recall using it as my main search engine at altavista.digital.com before they moved to get its own domain at altavista.com. [1] https://en.wikipedia.org/wiki/AltaVista https://en.wikipedia.org/wiki/AltaVista
- macintux 3y agoI remember when AltaVista was the best, and despairing because it was so terrible. At a dinner party, we were arguing about how to move forward with discovery on the web, because the situation was so dire. Someone was arguing for keyword registration, a la AOL. I really, really hope that someone wasn’t me; I’ve convinced myself over the years it wasn’t, but I didn’t have any better ideas, just knew that wouldn’t work.
- dang 3y agoRelated: How SSH got port number 22 - https://news.ycombinator.com/item?id=33363795 https://news.ycombinator.com/item?id=33363795 - Oct 2022 (2 comments) How SSH Port Became 22 - https://news.ycombinator.com/item?id=21350246 https://news.ycombinator.com/item?id=21350246 - Oct 2019 (81 comments) How SSH port became 22 - https://news.ycombinator.com/item?id=17552100 https://news.ycombinator.com/item?id=17552100 - July 2018 (95 comments) How SSH got port number 22 - https://news.ycombinator.com/item?id=14178091 https://news.ycombinator.com/item?id=14178091 - April 2017 (207 comments)
- ChrisArchitect 3y ago(2017) Was this article updated recently in some way? Not sure why it's mentioned at top of page, maybe just appended for posterity. HN discussion then: https://news.ycombinator.com/item?id=14178091 https://news.ycombinator.com/item?id=14178091
- dang 3y agoAh thanks! I've updated the list above.
- danielvaughn 3y agoI’ve always wanted to see something like a common port dictionary or encyclopedia. Just a big list of all the ports, each with their common usage and the history behind it.
- presentmonkey 3y agoThere's this wiki page that's pretty cool https://en.m.wikipedia.org/wiki/List_of_TCP_and_UDP_port_numbers https://en.m.wikipedia.org/wiki/List_of_TCP_and_UDP_port_num...
- skissane 3y agoWikipedia's list is better than the official one because it explains what some of those protocols actually are – especially the early ones which don't have any RFC specified in IANA's registry. Although, in several cases, there is an RFC, even though IANA's registry doesn't record it. For example, port 1 (tcpmux / TCP Port Service Multiplexer) uses a protocol defined by RFC1078, as Wikipedia's article on it helpfully explains – https://en.wikipedia.org/wiki/TCP_Port_Service_Multiplexer https://en.wikipedia.org/wiki/TCP_Port_Service_Multiplexer – but IANA's registry doesn't mention that. Or similarly, port 5 is listed as rje / Remote Job Entry in the registry, but Wikipedia helpfully notes that it is the protocol defined by RFC407 (and maybe RFC725 is a newer version of it?). I doubt that ARPANET RJE protocol (whose syntax resembles FTP, SMTP, etc) ever saw any great amount of implementation; I believe historically the most popular RJE protocols were IBM's (2780/3780 and later Network Job Entry / NJE which was used in RSCS, most notably on BITNET) – but those protocols don't have an assigned port number, since they don't natively run on top of TCP/IP. There are however some historical mysteries in this IANA registry for which even Wikipedia does not know the answer: the first of many is what ports 2 and 3, "compressnet", were used for. (Edit: What Wikipedia doesn't know, HN does: https://news.ycombinator.com/item?id=37016159 https://news.ycombinator.com/item?id=37016159
- hiAndrewQuinn 3y agoSeconded. I made some Anki cards out of the table of the "Well-known ports" table and it has proven surprisingly helpful fingertip knowledge for my kind of work (Linux systems and small scale networks in odd places).
- aussieguy1234 3y agoI always figured FTP is port 21, SFTP/SSH is port 22
- IronWolve 3y agoThey seem to always leave off port 20 is also ftp.
- grepfru_it 3y agoIt’s just a data channel. This changed with nat and the introduction of the PASV command which allowed the client to set a non-well known port for the data channel
- oarsinsync 3y ago> the introduction of the PASV command which allowed the client to set a non-well known port for the data channel PASV instructs the server to specify another ip:port that it’s listening on to enable the client to connect. PORT expects there to be an open port on the client for the server to connect to.
- broodbucket 3y agoThat's exactly what TFA says?
- joak 3y agoAnnounced officially to the mythical cypherpunks@toad.com mailing list... Fighting to legalize cryptography on the internet. PGP was banned. Sending encrypted emails was illegal... Cypherpunks won. Thanks to them.
- IAmNotACellist 3y agoConspiracy-minded theory: only once the government successfully arranged for a process (behind closed doors) to subvert or capture any US-based cryptography efforts or communications.
- tptacek 3y agoWhere were you that PGP was banned, or encrypting emails was illegal?
- mratsim 3y agoCryptography was considered a war weapon and only allowed for military use. The United States had to be brought to court to finally allow cryptography: https://en.m.wikipedia.org/wiki/Bernstein_v._United_States https://en.m.wikipedia.org/wiki/Bernstein_v._United_States > Years before, the government had placed encryption, a method for scrambling messages so they can only be understood by their intended recipients, on the United States Munitions List, alongside bombs and flamethrowers, as a weapon to be regulated for national security purposes. Companies and individuals exporting items on the munitions list, including software with encryption capabilities, had to obtain prior State Department approval. — Electronic Frontier Foundation: EFF's History Before that, export rules could be "worked around" by printing cryptography in books. See also https://en.m.wikipedia.org/wiki/Export_of_cryptography_from_the_United_States https://en.m.wikipedia.org/wiki/Export_of_cryptography_from_...
- tiernano 3y agonot quite crypto related, or at least directly, i remember this old Mac G4 ad: https://youtu.be/lb7EhYy-2RE?si=3tvJK4BXbA71LbGQ https://youtu.be/lb7EhYy-2RE?si=3tvJK4BXbA71LbGQ
- j16sdiz 3y agoI wonder if IANA still assign numbers? Can I have them assign ports for, say, redis?
- sgjohnson 3y agoYes, they do. Their mission hasn’t changed since IANAs inception. But getting a port assignment these days is going to be virtually impossible. It’s probably not going to happen without at least a Proposed Standard RFC. https://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml?search=rdp&search=&page=2 https://www.iana.org/assignments/service-names-port-numbers/... There’s not a single RFC published that concerns redis. It’s not going to happen.
- ivlad 3y agoI got a port assigned a few years ago. I needed to write a justification why the organisation I represented needs a port number (a custom binary protocol), a formal confirmation that protocol has versioning built-in (so we will not request for a new port number for the next version of the protocol), a confirmation that we have a running code implementing the protocol (if I recall correctly, link to documentation was sufficient), and the reasons why we cannot use any of the existing protocols. It’s not impossible and I think it’s totally doable for redis unless the port is already reserved for something else.
- dmurray 3y agoProbably for the best. If there was a moderately complicated bureaucratic process to be assured of getting one, it wouldn't be Redis or the next SSH that got assigned ports. It would be Oracle or HP or someone else incapable of pretending to be a good Internet citizen, who filled in 10,000 of the forms promising that they have 10,000 totally necessary well known enterprise services.
- chupasaurus 3y agoSomeone should steal 666 TCP/UDP, no RFC and contact email is of a person who leaved id in 1996.
- 3y ago
- a-dub 3y agoreminds me of the days when s/keys over telnet were cool. there should be a vh1 where are they now special for assigned ports in /etc/services that shipped with early slackware.
- SeanLuke 3y agoThe headline of the article does not match the posting, which breaks a rule I believe. Could we at least correct the posting's grammar? To "How SSH became Port 22".
- acer4666 3y ago"The -p <port> option can be used to specify the port number to connect to when using the ssh command on Linux. The -P <port> (note: capital P) option can be used with SFTP and scp." The most annoying thing about SSH/scp!
- dijit 3y agoI always just use -o port=<xx> for this reason.
- jbaber 3y agoWait, lower case 'o' works?
- ryan-duve 3y agoLooks like I've got BSD SSH installed. From `man ssh`: -o option Can be used to give options in the format used in the configura‐ tion file. This is useful for specifying options for which there is no separate command-line flag. For full details of the op‐ tions listed below, and their possible values, see ssh_config(5). `Port` is on the list underneath. So I think the idea is you run ssh -o <option_name> <option_value> where the first can be `--port`. This looks like it will be really handy for me for the exact reason GP said.
- lnxg33k1 3y agoI use rsync with -e 'ssh -p PORT', so that I can also have the ability to resume just in case :D, interesting how everyone has a different solution ^^, let's see how many ways of doing the same thing can we collect in this thread
- lloeki 3y agoAnother one is places where you can use `user@host` and those where you can't and have to use `-l user` (and thus have to use `-e 'ssh -l user'` or equivalent) Usually I use per host `ssh_config(5)` (both for port and user) but some tools also don't make use of that!
- Jakesbeb 3y ago[flagged]
- donalhunt 3y agoHad a very similar experience when I requested a Private Enterprise Number (PEN) in the early 00s. I was doing some experimentation with LDAP, mailman and identity based encryption and needed some OIDs to support my undergraduate project work. Private Enterprise Numbers are identifiers that can be used in SNMP configurations, in LDAP configurations, and wherever the use of an ASN.1 object identifier (OID) is appropriate. So I went about signing up my university for a PEN. It helped that I also worked for the IT Services team at the time but I distinctly remember the request being done by email with the response more of less being "here's your number". :) To my knowledge, I believe I'm the only person who has made use of the PEN assigned to the university.
- mjlee 3y agoWhy 22 was available is also interesting. Network Control Protocol was the precursor to TCP and used different ports for inbound and outbound traffic, typically even for outbound and odd for inbound. If you look in /etc/services you'll notice that all the older protocols listen on odd numbered ports. Some of this still survives today. In active mode FTP servers listen on 21, ACK the inbound request and then connect to the client from 20.
- macintux 3y agoI do not miss the days of trying to figure out which FTP mode would work through a given firewall configuration.
- deleted 3y ago[deleted]
- imaginator 3y agoThis is a good example of make it easy for others to say yes.
- teddyh 3y ago> I designed SSH to replace both telnet (port 23) and ftp (port 21). As I have written here previously¹, that’s actually a bit of revisionist history, or at least a significant omission. Speaking as someone who was actually using Unix systems when this happened, the "ssh" command was replacing the rsh command, and also still ships an "slogin" command, replacing rsh’s companion command, "rlogin" (and "scp" replaced "rcp"). Where I was, nobody was even using telnet or FTP internally; everybody was using rsh, rlogin and rcp! This also better explains the naming; going from "rsh" to "ssh" is easier. If someone had wanted to make telnet encrypted, they would just have had to implement the standard telnet protocol and add another option in the protocol; it has a bunch already, and even one for encryption, IIRC. 1. <https://news.ycombinator.com/item?id=14178333 https://news.ycombinator.com/item?id=14178333>
- throw0101c 3y ago> If someone had wanted to make telnet encrypted, they would just have had to implement the standard telnet protocol and add another option in the protocol […] This document describes a the telnet encryption option as a generic method of providing data confidentiality services for the telnet data stream. While this document summarizes currently utilized encryption types and codes, it does not define a specific encryption algorithm. Separate documents are to be published defining implementations of this option for each encryption algorithm. * https://datatracker.ietf.org/doc/html/rfc2946 https://datatracker.ietf.org/doc/html/rfc2946
- teddyh 3y agoSo I did recall correctly, then.
- kloch 3y ago> Speaking as someone who was actually using Unix systems when this happened, the "ssh" command was replacing the rsh command, A different data point: I was also a Unix sysadmin at the time (thought just out of school) and for me ssh replaced telnet and ftp. I never used rsh, rlogin, and rcp except when testing exploits.
- pantulis 3y ago> We have assigned port number 22 to ssh, with you as the point of contact. Joyce Those were the early days when you could be designated as the point of a contact for a TCP port connection number and expect not to be swamped by emails!
- notbeuller 3y agoI used to have a registered port (in the 3000s) - didn’t get a lot of spam, but once I got a very angry phone call (!!!) from someone that tracked me down because their firewall blocked an incoming request in that port. They did their own research and decided it was my fault.
- kshay 3y agoI like how he didn’t explicitly request 22. It was more like “anything 1-255 would be great... oh, by the way, I happen to be using 22...”
- hk__2 3y agoHe did request it: > It would be great if this number could be used
- hk__2 3y agoFrom: Tatu Ylonen <ylo@cs.hut.fi> To: Internet Assigned Numbers Authority <iana@isi.edu> Subject: request for port number Organization: Helsinki University of Technology, Finland Was "Organization" a common email header at the time? This is the first time I see it.
- dannyobrien 3y agoYes!
- teddyh 3y agoMany e-mail client still has a field for it in its account settings.
- FredPret 3y agoSSH is the most fantastic piece of black magic. So many incredible things are easy and secure. Port forwarding Reverse port forwarding Rsync So much more. And it's free. What a privilege to be alive today - I remember when all this was just a dream.
- emmelaich 3y agossh also used to use source port 22. At least a popular implementation of it did. A bit of websearching didn't find it; anyone else remember this?
- zamadatix 3y agoWouldn't that have meant you couldn't ssh out of a machine running an ssh server since the port was already bound to another process?