Live data from Hacker News

OpenSSH 10.5/10.5p1

openssh.org

1–10 of 34 posts

Re: OpenSSH 10.5/10.5p1

#3
"[..] a security bug identified by AI tools is subsequently independently discovered by a different researcher. This suggests that adversaries who do not report bugs to OSS projects are likely to be able to discover these bugs too. Given this, the OpenSSH team will, for now, be making more frequent releases to get bugfixes into users' hands more quickly rather than batching them until the next planned release."

Re: OpenSSH 10.5/10.5p1

#4
Glad they're not letting potential high false positive rate preclude discovery of true positives. Better to get a lot of noise with a little bit of signal, if the alternative was not get that signal at all.

Re: OpenSSH 10.5/10.5p1

#6
post #5
post #2

Am I crazy to think this title is just incorrect? They say AI reports are welcome, not fixes.

That was sloppy work on my part. Updated.

If you still have the ability to edit it, looks like there's a typo in the word "assistance"
Post reply on HN