Re: OpenSSH3.5p1 vs. Commercial SSH 3.2

From: ftbee (ft0bee@hotmail.com)
Date: 01/27/03


From: ftbee <ft0bee@hotmail.com>
Date: Mon, 27 Jan 2003 22:23:53 +0200

Nico Kadel-Garcia wrote:
> "ftbee" <ft0bee@hotmail.com> wrote in message
> news:b0u1vg$ge9$1@oravannahka.helsinki.fi...
>
>>OpenSSH is a nice piece of software, however SSH 3.2 is still way ahead
>>of OpenSSH for the current stage. SSH is more feature-rich, provide more
>>fine-turnings and most importantly has less security problems in recent
>>years than OpenSSH (doing a query in bugtraq you'll see the difference).
>
>
> Horse twaddle. The OpenSSH bugs have been fixed *WAY* ahead of identical
> ssh.com issues

Agree! I believe it'll stay this way. By the way if you don't like the
word "way ahead" I take it back :). Let's say currently OpenSSH has a
*LITTLE BIT* more problems than SSH2.

> (due to similar original code bases).

this is only true for SSH protocol 1, OpenSSH's protocol 2 code has
little to do with the original code.

>It is the openness of
> the OpenSSH code and its heavy use in freeware environments that gets these
> noticed and fixed so quickly, not the lack of such issues for ssh.com's
> code.
>
>



Relevant Pages

  • Re: two SSH compatibility scenarios: can it work?
    ... We are required to use SSH to log into the Engineering lab machines. ... > server software displays this header upon telnet connection to port 22. ... I still use Windows on my notebook for application compatibility. ... > running OpenSSH 3.4p1. ...
    (comp.security.ssh)
  • Re: OpenSSH, Telnet, Windows Authentication and double-hops
    ... deployment on a Windows network. ... Does this mean that you are setting SSH port forwarding ... does not provide the other side with either a Kerberos ticket, ... We're focusing on the OpenSSH for Windows distribution. ...
    (comp.security.ssh)
  • Re: ssh compatability issues
    ... >> without keeping two versions of ssh around on my home computer. ... running the OpenSSH server that comes with Solaris ... By 'some old security problems with that' I was not sure if you meant ...
    (comp.security.ssh)
  • Re: Solaris 9 SSH: HostbasedAuthentication?
    ... > Subject: Solaris 9 SSH: HostbasedAuthentication? ... > authentication. ... I'm gathering that the OpenSSH version it's based on didn't have ...
    (Focus-SUN)
  • Re: [openssh-unix-announce] Re: Upcoming OpenSSH vulnerability (fwd)
    ... Is OpenSSH 3.3 now part of the base system? ... older versions of ssh are vulnerable or not. ... I have to say that I side with Theo here: ... we wouldn't need OpenSSH. ...
    (FreeBSD-Security)