OpenSSH 10.5/10.5p1
openssh.org
OpenSSH 10.5/10.5p1
1–10 of 34 posts
Re: OpenSSH 10.5/10.5p1
#2Am I crazy to think this title is just incorrect? They say AI reports are welcome, not fixes.
Re: OpenSSH 10.5/10.5p1
#3"[..] a security bug identified by
AI tools is subsequently independently discovered by a different
researcher. This suggests that adversaries who do not report bugs
to OSS projects are likely to be able to discover these bugs too.
Given this, the OpenSSH team will, for now, be making more frequent
releases to get bugfixes into users' hands more quickly rather than
batching them until the next planned release."
Re: OpenSSH 10.5/10.5p1
#4Glad they're not letting potential high false positive rate preclude discovery of true positives. Better to get a lot of noise with a little bit of signal, if the alternative was not get that signal at all.
Re: OpenSSH 10.5/10.5p1
#5Am I crazy to think this title is just incorrect? They say AI reports are welcome, not fixes.
That was sloppy work on my part. Updated.
Re: OpenSSH 10.5/10.5p1
#6Re: OpenSSH 10.5/10.5p1
#7Re: OpenSSH 10.5/10.5p1
#8> ssh(1): add a "ssh -Z user@host" mode that prints the keys that
will be tried for public key authentication in the order that
they will be used.
Oh, that's a nice new feature:)
Re: OpenSSH 10.5/10.5p1
#9No, AI assistance is NOT welcome in general. They mention security bug reports, so using AI like ASAN etc. is welcome.