OpenSSH 10.5/10.5p1

(openssh.org)

64 points | by voxadam 2 hours ago

7 comments

  • alpn 1 hour ago
    "[..] a security bug identified by AI tools is subsequently independently discovered by a different researcher. This suggests that adversaries who do not report bugs to OSS projects are likely to be able to discover these bugs too. Given this, the OpenSSH team will, for now, be making more frequent releases to get bugfixes into users' hands more quickly rather than batching them until the next planned release."
  • yjftsjthsd-h 1 hour ago
    > ssh(1): add a "ssh -Z user@host" mode that prints the keys that will be tried for public key authentication in the order that they will be used.

    Oh, that's a nice new feature:)

  • 3asj176 1 hour ago
    No, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.
    • akerl_ 1 hour ago
      > No, AI assistance is NOT welcome in general.

      Can you cite that? I see them specifically welcoming AI security reports; I don't see any evidence that other AI submissions are not welcome.

      • asveikau 32 minutes ago
        These policies seem to be often evolving lately in many projects, but I believe OpenBSD (the project OpenSSH is contained inside) is currently skeptical of AI generated code contributions at this point in time.

        For example, I found this on a Google search, here is a thread from Theo, the project leader, about LLM output and copyright, where he says they can't accept it into the tree on copyright grounds. https://marc.info/?l=openbsd-tech&m=177425035627562&w=2

        Elsewhere in the thread he implies using it for a code review tool is ok

        • minimaltom 8 minutes ago
          Idk if its accurate to rote project the policies of OpenBSD to OpenSSH, yes technically its a subproject but in practice stewardship and thus effective policy is pretty much all damien.
      • as12qh 54 minutes ago
        The AI boosters should look for evidence that they do allow AI contributions! Why would they mention in the release notes that AI security bug reports are welcome if they allowed AI in general anyway?
    • swingandamiss 36 minutes ago
      Why is AI assistance not welcome?
    • mmooss 24 minutes ago
      They plainly, explicitly welcome it:

      "Recently the OpenSSH team have received a large number of security bug reports, many of which are findings from AI models or made with AI assistance. While many AI reports are determined not to have security impact when considered in the context of a realistic threat model, we very much welcome these reports, especially when combined with human triage, analysis, test-cases and particularly when accompanied by proposed fixes."

      • 1sahG 21 minutes ago
        AI is really rotting the mind, as seen from various sealions and people who no longer understand basic text in this comment section.
    • rvz 1 hour ago
      You need to understand that they have no choice.

      Attackers are going to use AI models to find bugs or 0 days quicker than those without it and of course they will not report them.

      So it only makes sense to allow it and accept (valid) AI reports from reputable security researchers to keep ahead before a bug gets exploited in a vulnerable release.

      As long as the submitter shows their understanding of the reported bug means and what the change is, it is fine to do so, with the reviewers gating invalid reports.

      > so using AI like ASAN etc. is welcome.

      AddressSanitizer is not "AI", nor does it use AI. [0]

      [0] https://static.googleusercontent.com/media/research.google.c...

      • dpoloncsak 1 hour ago
        Yeah, I'd rather a secure OpenSSH than an AI free one. I appreciate users taking stands and drawing hard lines in the sand, but I think exemptions for large foundations of networking in general should be made, as like you said, threat actors don't care much about AI assistance and will happily use any 0-days it finds.
        • frumplestlatz 46 minutes ago
          If you need to make exemptions for critical code because you must admit that AI is undeniably of significant utility, it's pretty foolish to still apply a blanket "hard stand" against it elsewhere.

          AI is here, and it's not going anywhere. It's not going to be pretty, but the people that are going to be hit the hardest are those who cannot -- or worse, refuse to -- adapt.

          I'm sympathetic -- I feel both a loss and an existential dread. I've also never, in my 30 years in my field, seen something sweep the technology space so quickly and change things so much overnight, and I see no chance of it stopping anytime soon.

          • dpoloncsak 4 minutes ago
            I agree with you, but I can also understand the perspective of someone who thinks, (pulling this example out of my ass) that using LLMs to review if your AAA game is 'un-cheatable' may be a misappropriate of the resources required to do so.
      • as12qh 51 minutes ago
        I'm not a native speaker, but in other languages the cited text clearly means "using AI in the manner of ASAN or similar tools".
  • 4L3XV33 1 hour ago
    Glad they're not letting potential high false positive rate preclude discovery of true positives. Better to get a lot of noise with a little bit of signal, if the alternative was not get that signal at all.
  • jscd 1 hour ago
    Am I crazy to think this title is just incorrect? They say AI reports are welcome, not fixes.
    • voxadam 1 hour ago
      That was sloppy work on my part. Updated.
      • saghm 1 hour ago
        If you still have the ability to edit it, looks like there's a typo in the word "assistance"
        • voxadam 1 hour ago
          It's just not my day.
          • JoshTriplett 1 hour ago
            "AI assistance" is still not welcome in general. AI security reports are.
            • akerl_ 59 minutes ago
              Is that the case? I see this note focusing on AI reports in the release notes, and I've poked around the OpenSSH project more generally and don't see any indication that they don't accept or welcome other AI inputs.
  • hn2crljhhy 34 minutes ago
    [dead]
  • gertrunde 33 minutes ago
    Wow... What have they done to that webpage to make it that unreadable?

    And why?

    Ouch.