3 ms·
OpenSSH 10.5/10.5p1
- jscd 2mo agoAm I crazy to think this title is just incorrect? They say AI reports are welcome, not fixes.
- voxadam 2mo agoThat was sloppy work on my part. Updated.
- saghm 2mo agoIf you still have the ability to edit it, looks like there's a typo in the word "assistance"
- voxadam 2mo agoIt's just not my day.
- JoshTriplett 2mo ago"AI assistance" is still not welcome in general. AI security reports are.
- akerl_ 2mo agoIs that the case? I see this note focusing on AI reports in the release notes, and I've poked around the OpenSSH project more generally and don't see any indication that they don't accept or welcome other AI inputs.
- saghm 2mo agoI'm a terrible typist, so I can't criticize. Lately I've noticed I end up needing to edit what seems to be the majority of my comments because I notice typos shortly after posting them. Hopefully this comment isn't one of them!
- nickysielicki 2mo agoThey say AI reports are welcome, especially when corroborated by human triage, and/or when accompanied by fixes (unconstrained by any adjective, eg human or otherwise).
- alpn 2mo ago"[..] a security bug identified by AI tools is subsequently independently discovered by a different researcher. This suggests that adversaries who do not report bugs to OSS projects are likely to be able to discover these bugs too. Given this, the OpenSSH team will, for now, be making more frequent releases to get bugfixes into users' hands more quickly rather than batching them until the next planned release."
- cromka 2mo agoMeanwhile Zig developers: not even a spell check fix using AI will get accepted
- 4L3XV33 2mo agoGlad they're not letting potential high false positive rate preclude discovery of true positives. Better to get a lot of noise with a little bit of signal, if the alternative was not get that signal at all.
- yjftsjthsd-h 2mo ago> ssh(1): add a "ssh -Z user@host" mode that prints the keys that will be tried for public key authentication in the order that they will be used. Oh, that's a nice new feature:)
- ahartmetz 2mo agoYeah, I've occasionally had to divine from verbose debug output that the remote host didn't like more than three or so public key attempts before requiring another auth type.
- ghshephard 2mo agoI don't think there has been a single month in the last 5 years that I haven't had to figure out which public-key was used to authenticate me to a host via `ssh -vv` - often to let someone else who is failing to connect know which key to use. The `-Z` is less useful - as I almost always know exactly which and what order the public keys are - as most of our sshd instances fail after 5 attempts - so making sure either (A) the correct ones or used or (clumsily, B) - just putting the correct one in the first five to try. Would be a nice feature to echo which key successfully worked.
- stingraycharles 2mo agoYup, or the alternative: is authentication failing because I have too many public keys and it just stopped trying after N keys?
- ghshephard 2mo agoI do not want to confess how often I just drop in and change the order of my approximately dozen or so keys at the end of the ssh config file just to get the ones I want up to the top of the list.
- seethishat 2mo agoThis is why I keep a ~/.ssh/config file. I store all the hosts and various connection parameters (uernames, alternate ports, keys, etc.) in that file. Would that work for you?
- 3asj176 2mo agoNo, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.
- rvz 2mo agoYou need to understand that they have no choice. Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them. So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release. As long as the submitter shows their understanding of the reported bug means and what the change is, it is fine to do so, with the reviewers gating invalid reports. > so using AI like ASAN etc. is welcome. AddressSanitizer is not "AI", nor does it use AI. [0] [0] https://static.googleusercontent.com/media/research.google.com/en//pubs/archive/37752.pdf https://static.googleusercontent.com/media/research.google.c...
- dpoloncsak 2mo agoYeah, I'd rather a secure OpenSSH than an AI free one. I appreciate users taking stands and drawing hard lines in the sand, but I think exemptions for large foundations of networking in general should be made, as like you said, threat actors don't care much about AI assistance and will happily use any 0-days it finds.
- frumplestlatz 2mo agoIf you need to make exemptions for critical code because you must admit that AI is undeniably of significant utility, it's pretty foolish to still apply a blanket "hard stand" against it elsewhere. AI is here, and it's not going anywhere. It's not going to be pretty, but the people that are going to be hit the hardest are those who cannot -- or worse, refuse to -- adapt. I'm sympathetic -- I feel both a loss and an existential dread. I've also never, in my 30 years in my field, seen something sweep the technology space so quickly and change things so much overnight, and I see no chance of it stopping anytime soon.
- hn2crljhhy 2mo ago[dead]
- gertrunde 2mo agoWow... What have they done to that webpage to make it that unreadable? And why? Ouch.
- qudat 2mo agoDarn, still no host headers so we can reverse proxy on a single ip
- throw0101a 2mo ago> Darn, still no host headers so we can reverse proxy on a single ip How would this be done? After the "SSH-2.0" banner, the first packet is SSH_MSG_KEXINIT and there's no space in that for a "Host" header: * https://datatracker.ietf.org/doc/html/rfc4253#section-7.1 https://datatracker.ietf.org/doc/html/rfc4253#section-7.1
- djmdjm 2mo agoIf we did this in SSH then I think we should do it properly and take inspiration from TLS ESNI https://datatracker.ietf.org/doc/draft-ietf-tls-esni/25/ https://datatracker.ietf.org/doc/draft-ietf-tls-esni/25/
- stragies 2mo agoYou could wrap a TLS-connection around your SSH-connection, and then use the ALPN to indicate SSH, so that your reverse proxy knows, what to do with it.