Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
OpenSSH cutting edge
Federico Biancuzzi, 2005-12-19

Federico Biancuzzi interviews OpenSSH developer Damien Miller to discuss features included in the upcoming version 4.3, public key crypto protocols details, timing based attacks and anti-worm measures.

Comments Mode:
OpenSSH cutting edge 2005-12-21
Alex Blewitt (1 replies)
Re: OpenSSH cutting edge 2005-12-21
Kelly Martin
Editorial: alter use of HTML-comments 2005-12-21
Anonymous (1 replies)
OpenSSH cutting edge 2005-12-21
Anonymous (4 replies)
Re: OpenSSH cutting edge 2005-12-21
Anonymous (1 replies)
Your implication is that it is safe to allow ssh to pass through the firewall from untrusted inside hosts/users today, but will become hopelessly less so after openssh implements more functional tunnels, and that the openssh team should therefore not provide such functionality.

However, your first implication is simply false - if you, as firewall admin, are allowing ssh from inside hosts today on tcp/22 due to the presumption that those connections are ONLY used for ssh or ONLY used for textual connections, then you are already making a mistake.

SSH already allows tunneling arbitrary ports. There are in turn many ways to funnel entire networks through those single-port tunnels already, so the assumption that this is an increase in exposure is false.

On the other hand there are good reasons to appreciate the increased functionality in openssh. It's just one more tool in the hands of Unix users, and the more tools we have the more flexibility we have. I'm looking forward to the new version, and I really appreciate the effort of the developers.



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/375/32845#32845
Re: Re: OpenSSH cutting edge 2005-12-22
Anonymous
Re: OpenSSH cutting edge 2005-12-21
Anonymous (1 replies)
Re: Re: OpenSSH cutting edge 2005-12-29
Anonymous
Re: OpenSSH cutting edge 2005-12-22
Anonymous (1 replies)
Re: Re: OpenSSH cutting edge 2005-12-29
Anonymous
Re: OpenSSH cutting edge 2005-12-22
Anonymous
TCP over TCP considered harmful 2005-12-22
Anonymous (3 replies)
Re: TCP over TCP considered harmful 2005-12-22
Anonymous (1 replies)
Re: TCP over TCP considered harmful 2006-01-03
Baron von Leezard
Brute force attack 2005-12-22
Jules
OpenSSH cutting edge 2006-01-03
Anonymous (2 replies)
Re: OpenSSH cutting edge 2006-01-07
communIT
Re: OpenSSH cutting edge 2007-11-10
Anonymous
OpenSSH cutting edge 2006-01-24
Chris Kendon







 

Privacy Statement
Copyright 2007, SecurityFocus