Live data from Hacker News

Undisclosed hole in openssh on FreeBSD and Juniper?

thread.gmane.org

11–20 of 47 posts

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#12
Many years ago, I submitted a bug report to OpenBSD about an issue I had discovered with threads. I received a one line response from Theo. I still have the mail. He wrote:

   "Threads are for idiots."
At the time, I felt discounted and I was upset. I was younger then. Today, I realize what he meant and that he's right.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#13

Many years ago, I submitted a bug report to OpenBSD about an issue I had discovered with threads. I received a one line response from Theo. I still have the mail. He wrote: "Threads are for idiots." At the time, I felt discounted and I was upset. I was younger then. Today, I realize what he meant and that he's right.

> I realize what he meant and that he's right.

Could you please expand on this?

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#14
This is unsettling, to be sure. If there's anything to this, I'd really love to hear a response from the actual FreeBSD folks.

But it should be noted that this guy has a relatively rocky history with *BSD, and his nearly context-free, ambiguous trash-talking of FreeBSD should be taken with a grain of salt.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#15
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSL consumers - only when they have a fix? It could be best fixed in OpenSSL itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.

OpenSSH is a SSH client and server provided by the Open BSD Foundation.

OpenSSL is an encryption API maintained by an entirely different group of people.

EDIT: Modified my reply. OpenSSH at some point moved it's "restrictively licenced software" (RSA, DES, etc) out of it's codebase and now depends on OpenSSL according to it's license. http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/LICENC...

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#16
post #15

Earlier quoted context omitted.

It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSL consumers - only when they have a fix? It could be best fixed in OpenSSL itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.

OpenSSH is a SSH client and server provided by the Open BSD Foundation. OpenSSL is an encryption API maintained by an entirely different group of people. EDIT: Modified my reply. OpenSSH at some point moved it's "restrictively licenced software" (RSA, DES, etc) out of it's codebase and now depends on OpenSSL according to it's license. http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/LICENC...

Quite right, my typo, and if I could still 'edit' my post I'd correct it. I meant OpenSSH:

It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSH consumers - only when they have a fix?

It could be best fixed in OpenSSH itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#17
post #15

Earlier quoted context omitted.

It could be that they plan to tell FreeBSD - and therefore expose what they've found, now they've suddenly started auditing OpenSSL consumers - only when they have a fix? It could be best fixed in OpenSSL itself, and only affecting those using the compiler options or SSH configuration that FreeBSD ships with.

OpenSSH is a SSH client and server provided by the Open BSD Foundation. OpenSSL is an encryption API maintained by an entirely different group of people. EDIT: Modified my reply. OpenSSH at some point moved it's "restrictively licenced software" (RSA, DES, etc) out of it's codebase and now depends on OpenSSL according to it's license. http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/LICENC...

Actually somebody posted the contrary yesterday and I thought the same as you. We're both wrong - I went off and checked the openssl license and it lists a couple of things that are included from OpenSSL and a short grep in the code turns up a lot of references to OpenSSL.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#18
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

I can see that you have not interacted with Theo before. Sometimes these things are just all personality.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#19
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

Short Answer: Bitterness.

Long Answer: It's complicated and I do not understand the whole picture myself.

I can however outline two things that likely exasperate the situation.

a) OpenSSH is used by nearly everyone. Nearly every unix-like installation includes a copy of OpenSSH. Most companies which do business on the internet use a unix-like operating system in some way.

The OpenBSD Foundation has had trouble obtaining funding to cover operating costs in the past. Included in these operating costs is support and auditing of OpenSSH.

b) There has been a long and colored history between FreeBSD and OpenBSD. A lot of code and features developed under OpenBSD has been ported over to FreeBSD such as the OpenBSD Packet Filter (PF).

Juniper uses FreeBSD and PF in their routers and have donated in various ways to FreeBSD. For example, Juniper donated three EX3200s with full contracts to FreeBSD for use in their datacenter.

The OpenBSD Foundation on the other hand has not really seen the same support.

Re: Undisclosed hole in openssh on FreeBSD and Juniper?

#20
post #19
post #5

What good reason could their possibly be for not disclosing a hole to FreeBSD? Especially if it effects networking infrastructure.... 1. Government gag order? I'd call this a "good reason", but it wouldn't clear my conscience. 2. Disclosure to or interception by malicious parties? I can't imagine that the best solution would be STO.

Short Answer: Bitterness. Long Answer: It's complicated and I do not understand the whole picture myself. I can however outline two things that likely exasperate the situation. a) OpenSSH is used by nearly everyone. Nearly every unix-like installation includes a copy of OpenSSH. Most companies which do business on the internet use a unix-like operating system in some way. The OpenBSD Foundation has had trouble obtain…

Sure, De Raadt/OpenBSD are bitter about the lack of funding but that does not explain anything about this mysterious hole. This email can mean anything. Does Kirk McKusick know about this hole and has he pressured De Raadt not to disclose it (for what reason could that even be?), or is it a vague reference to a fallout he had with him earlier(making this an absurdly petty reason not to disclose it)?

Just dropping that hint is ambiguous drama baiting.

Post reply on HN