4 ms·
What is the difference between this and dropbear ssh?
by k8sToGo 3y ago
What is the difference between this and dropbear ssh?
- themoonisachees 3y agoI don't think there's much of one. The concept in itself isn't really useful, I've never seen someone go "you know the real problem with sshd? It's too bloated". It is slightly useful to put in smaller devices that don't have much space but I think it still relies on top many linux facilities to be an appropriate fix for that too. Still, cool project.
- dhon_ 3y agoI suspect the average openssh-server user just uses it for remote terminal access and copying files. Reducing the attack surface by dropping features and outdated standards is certainly valuable.
- maxcoder4 3y agoDropbear ssh is very useful when you have a full disk encryption on a remote server and want to be able to decrypt it after a reboot.
- Nextgrid 3y agoThere's technically no reason OpenSSHd can't also be used in this context. Maybe 2 decades ago there was a legitimate performance/disk space reason which is why Dropbear was preferred for this use case (and the convention remains to do this day), but nowadays the couple megabytes of difference in your initrd between using Dropbear and OpenSSH won't matter.
- m45t3r 3y ago> There's technically no reason OpenSSHd can't also be used in this context. For initrd you generally prefer static binaries. Not saying that OpenSSHd doesn't build statically, but having less code and dependencies makes it easier to statically compile. But yes, technically there is no reason to not use OpenSSHd, but in practice having a smaller and more self contained binary helps considering that you would want the bare minimum during initrd.
- chasil 3y agoThis server is very restricted compared to dropbear. -passwords are not allowed, only keys -only a single AEAD cipher is supported, and a single elliptic curve for key exchange -root cannot be locked out with this server -the key restrictions available in OpenSSH are not supported -the server does not use dynamic memory, and has a better security record than dropbear
- bjoli 3y agoIt is smaller and supports less features. Dropbear does password auth and x11 agent forwarding iirc.
- Columbo818 3y agoDropbear claims to be RFC-compliant, but isnt. Proof here: https://www.cvedetails.com/cve/CVE-2021-36369/ https://www.cvedetails.com/cve/CVE-2021-36369/ TinySSH doesnt claim to be compliant, and isnt. Does less in exchange for a reduced attack surface.
- mkj 3y agoThat CVE is a UI confusion issue in the client, I'm not sure exactly what bit the reporter thought was non-RFC compliant.
- ThreeHopsAhead 3y agodropbear has the goal of being small and light on ressources while still providing featurefull ssh support. tinyssh is small because it only implements a tiny subset of SSH that is needed for secure basic SSH connections. It only includes few crypto primitives excluding even RSA. There is considerable overlap in the two and you can reach something similar to tinyssh by compiling dropbear with only few select features, but tinyssh aims to be as secure and attack surface minimized as possible out of the box. Another notable difference: > no dynamic memory allocation - TinySSH has all memory statically allocated (less than 1MB)