OpenSSH’s latest update brings broader post-quantum warnings, a new username restriction, and some thoughts on security reporting in the age of AI.

Yesterday, longtime OpenSSH developer and maintainer Damien Miller reported on the openssh-unix-announce mailing list that OpenSSH 10.6 has been released as the go-to free and open way to SSH into servers and other remote hardware.
What I found most interesting about the announcement were some notes included by Miller on security in the age of AI. Unlike many other projects that have lately been complaining about the recent abundance of vulnerability reports being generated by AI, OpenSSH seems to welcome them, albeit with a few requests for those making the reports:
“Recently the OpenSSH team have received a large number of security bug reports, many of which are findings from AI models or made with AI assistance. While many AI reports are determined not to have security impact when considered in the context of a realistic threat model, we very much welcome these reports, especially when combined with human triage, analysis, test-cases, and particularly when accompanied by proposed fixes.”
That being said, although the release does contain 11 security fixes by my count, as well as many bugfixes, it’s not evident that they’re due to a surplus of AI-detected bugs and vulns.
Also, this new release isn’t all about keeping the software safe and working. OpenSSH also includes about a dozen new features. In another sign of the times, this includes mainstreaming the WarnWeakCrypto option that previously was only available for the OpenSSH client. It’s now enabled by default, and will create log entries whenever the client uses a key agreement scheme that’s not post-quantum safe.
Users should also note that one of the security fixes might cause a problem with some usernames. The dollar symbol and backslash are now disallowed when entered on the command line in order to avoid mischief from untrusted sources. This doesn’t affect usernames in configuration files, however, so the workaround is to put usernames containing the barred symbols in the SSH client’s configuration file using the User setting.
A complete list of security and bug fixes, as well as an in-depth look at new features — as well as all the information needed to download and install safely — is available in the release notice posted on OpenSSH’s website.
Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux





Be First to Comment