logoalt Hacker News

OpenSSH 10.5/10.5p1

113 pointsby voxadamyesterday at 5:49 PM35 commentsview on HN

Comments

alpnyesterday at 6:34 PM

"[..] a security bug identified by AI tools is subsequently independently discovered by a different researcher. This suggests that adversaries who do not report bugs to OSS projects are likely to be able to discover these bugs too. Given this, the OpenSSH team will, for now, be making more frequent releases to get bugfixes into users' hands more quickly rather than batching them until the next planned release."

yjftsjthsd-hyesterday at 6:40 PM

> ssh(1): add a "ssh -Z user@host" mode that prints the keys that will be tried for public key authentication in the order that they will be used.

Oh, that's a nice new feature:)

show 2 replies
4L3XV33yesterday at 6:35 PM

Glad they're not letting potential high false positive rate preclude discovery of true positives. Better to get a lot of noise with a little bit of signal, if the alternative was not get that signal at all.

qudatyesterday at 9:28 PM

Darn, still no host headers so we can reverse proxy on a single ip

show 1 reply
3asj176yesterday at 6:40 PM

No, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.

show 4 replies
jscdyesterday at 6:33 PM

Am I crazy to think this title is just incorrect? They say AI reports are welcome, not fixes.

show 2 replies
hn2crljhhyyesterday at 7:46 PM

[dead]

gertrundeyesterday at 7:47 PM

Wow... What have they done to that webpage to make it that unreadable?

And why?

Ouch.