▲ | VWWHFSfQ 6 days ago | |||||||
OpenSSH has actually been "pwned" numerous times though. It's a very desirable target. | ||||||||
▲ | rollcat 5 days ago | parent | next [-] | |||||||
I think in case of any security-critical project it's important to evaluate the track record objectively: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=OpenSSH It's true that there are 5 advisories so far in this year alone, but let's consider the actual impact:
OpenBSD enables sshd(8) in the default install, and has so far had two RCEs in 30 years. Now, not everyone runs OpenBSD, but I'd personally throw the stones at e.g. Debian (see CVE-2008-0166). | ||||||||
▲ | throwawaymaths 5 days ago | parent | prev [-] | |||||||
yeah and iirc erlang's ssl was one of the only ssl implementations not affected by heaetbleed since erlang is memory safe | ||||||||
|