- Package:
- openssh-client
- Source:
- openssh
- Description:
- secure shell (SSH) client, for secure access to remote machines
- Submitter:
- Fedor Brunner
- Date:
- 2024-07-09 02:03:03 UTC
- Severity:
- wishlist
- Tags:
Hi, it should be possible to suppress the exact package version of openssh that is reported during the initial protocol handshake also for ssh client. Similar bug was fixed for SSH server https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=562048 This patch adds DebianBanner option also to ssh_config. The behavior is the same as DebianBanner in sshd_config. Thanks, Fedor
Control: merge 774410 774411 This sort of patch carries an ongoing maintenance burden (and not an entirely trivial one; patches to the configuration-reading code normally conflict and require manual resolution when upgrading to new upstream versions), so you're going to have to make the case for why it's important in practice to conceal the client version. While I'm not wholly convinced that concealing the server version is interesting or valuable, surely vulnerabilities in that direction are orders of magnitude more common.
I understand that there is maintenance burden with each configuration-reading code, but this burden is already there for DebianBanner in sshd_config . The main use case for this switch is an user that wants to protect his privacy and don't want tell with each SSH connection which Debian (or Debian derivative) is he using. https://bugs.launchpad.net/ubuntu/+source/openssh/+bug/1195342/
Fedor Brunner <fedor.brunner@azet.sk> writes: This doesn't seem a very great benefit to me, and I'd agree with Colin that is doesn't seem likely to be worth the extra maintenance burden of carrying another patch vs upstream. Regards, Matthew
Broadcasting the client version is a serious privacy issue for those up against a network-level adversary (China/Iran activists, anybody GCHQ/NSA doesn't like). The important issue is timing correlation. Example: A) Activist creates anonymous website, uses SSH-over-TOR to update his website. B) Network-level adversary monitors network around his website, sees the activist is using SSH-2.0-OpenSSH_6.0p1 Debian-4+deb7u1. C) Activist updates SSH through apt-get dist-upgrade using his real IP. D) Activist updates his website using SSH-over-TOR. E) Network-level adversary now sees he is using SSH-2.0-OpenSSH_6.0p1 Debian-4+deb7u2. F) Network-level adversary checks their captured network data to see who downloaded the Debian-4+deb7u2 deb from security.debian.org or other mirrors during that time. There are other variations that don't require the adversary to monitor the traffic to the package mirrors. Example: A) Activist visits state run news site using his real IP. B) Activist uses SSH-over-TOR to write rebuttals to each news item. C) Network-level adversary sees when he upgrades his SSH version. D) Network-level adversary correlates that with visitors to their news site whose User-Agent version changed around the same time (of course limiting it to Debian users since for some reason the User-Agent strings report that). Even a traditional police adversary could use time correlation with no network monitoring needed. Seize the server, seize a suspect's TAILS CD, use /var/log/auth.log on the server to match the SSH client upgrade time with the timestamp the TAILS CD was burned. I'm sure there are many more but you get the idea. Leaking any information about the OS or package versions should always be avoided. Even if you can't think of a scenario that would abuse it does not mean that scenario doesn't exist.
Ahoj , Som Harris Bunbard, medzinárodný advokát, ktorý bol v kontakte s vaším príbuzným, krajanom a bratom Jozefom Rehákovou. Prostredníctvom našich rozhovorov som získal cenné informácie o jeho majetku, podnikaní a finančnom majetku. Ako jeho zákonný zástupca mám k dispozícii kópie jeho závetu, v ktorom jasne uvádza svoju rodinnú situáciu. Podľa závetu Jozef ako najbližších rodinných príslušníkov uviedol len dcéru a manželku. Nie je tam žiadna zmienka o bratovi alebo sestre, čo naznačuje, že bol jediným žijúcim dieťaťom svojich rodičov. Jeho príbeh odhaľuje, že sa narodil na Slovensku ako sirota a bol vychovaný britským inžinierom, ktorý mu nakoniec pred jeho odchodom v roku 2000 zveril celý svoj majetok a obchody. Jozef riadil tieto obchody a financie až do svojej nešťastnej náhody v roku 2022. Po jeho zániku som podrobne dohliadal na jeho účtovníctvo. Nedávno som bol informovaný, že americká vláda vykonáva audit jeho účtov a pripravuje sa na vrátenie daní a ďalšie konania kvôli blížiacim sa voľbám. Vyšlo najavo, že k podnikaniu a finančným majetkom Jozefa Rehákovej sa vyžaduje najbližší príbuzný. Vzhľadom na to, že Jozef nemal žiadnych známych príbuzných a že americká vláda vyžaduje na prevod majetku legitímneho príbuzného, navrhujem príležitosť, ktorá by mohla byť výhodná pre nás oboch. Tým, že sa prezentujete ako Jozefov brat, môžeme zabezpečiť, aby jeho bohatstvo zostalo v slovenskej komunite a nie aby ho pohltila americká vláda. Tento krok je tiež určený na ochranu mojej finančnej budúcnosti, keď sa budúci rok blížim k dôchodku. Ak ste ochotný v tejto veci spolupracovať, som pripravený poskytnúť vám všetku potrebnú dokumentáciu na overenie vášho vzťahu s Jozefom. Akonáhle budú aktíva oficiálne prevedené na vaše meno, môžeme rozdeliť výnosy podľa pomeru 60% - 40%. Na budúci rok plánujem navštíviť Slovensko, aby som ďalej diskutoval o našich spoločných investíciách. Ak chcete pokračovať, podeľte sa o svoje meno, telefónne číslo, osobnú e-mailovú adresu a kontaktné údaje. Na základe týchto informácií môžem banku informovať o vašej pripravovanej reklamácii. Musíme vytvoriť dôveru a čestnosť v našom partnerstve, aby sme zabezpečili úspech tohto úsilia. Teším sa na vašu rýchlu odpoveď a dúfam v obojstranne výhodnú spoluprácu. S pozdravom, Právnik Harris Bunbard ESQ