What is present advice about OpenSSH/SSH/SSHD cve-2024-6387

Started by PerpetualNewbie, July 01, 2024, 06:15:10 PM

Previous topic - Next topic
Quote from: seed on July 03, 2024, 05:12:24 PM
I also do not understand why people become angry so easy.

Because they dont understand that using opnsense is a privilege. The fact that opnsense offers so much for free is not enough for them. No. They want opnsense developers to respond to their emails or posts right away and fix bugs or implement features that they want immediately because product X or product Y already has those features. They literally act like a entitled spoiled brats. If their wishes are not fulfilled in timely matter, they either start bashing developers for being lazy and irresponsible or they "threat" that they will switch to alternative solution X or Y.

God forbid they make a donation or buy Deciso hardware when opnsense is working as expected.

Quote from: seed on July 03, 2024, 05:12:24 PMWhen the community version support is not enough for one, go bui a business licence and escalate this on the support side.

Exactly. Or go use something else.

Quote from: seed on July 03, 2024, 05:12:24 PMThere are a lot of others that enjoy OPNsense and its high frequency patch releases and community.

Exactly. Im thankful for this wonderful piece of free software.

Quote from: Patrick M. Hausen on July 03, 2024, 05:35:26 PM
Who's getting angry? The only person in this discussion insulting others is @alex303.

Im getting angry. However, im not insulting anyone. Im sorry if you somehow recognized yourself in what i wrote.

I commit a lot to OPNsense. If it would be closed source I couldn't do that anymore.  :'(

Theres also lots of other comitters. Its great that its open source.
Hardware:
DEC740

I found that line insulting:
QuoteIt might. World war 3 might happen tomorrow. See where im going with this ? This whole thing is so blown out of proportions its ridiculous.

And that one - not directed at myself, though:
QuoteLeave the IT space and go do something else.

And I stand by my verdict that VPN and SSH are ultimately equivalent technologies and in this specific setting layering does not buy you anything unless your outer layer is proven secure - which we probably both know does not exist outside of small theoretical example programs in universities. This is backed by 30 years of experience including consulting for state agencies.

An RCE in SSH or any VPN technology for that matter is the absolute worst case. I hope we can agree on that. And I did not see anyone in this thread demand Deciso fix it *now*.

After a more thorough assessment it seems to be the general consensus that FreeBSD can be considered safe unless proven otherwise. And we will get a patch next week.

The initial advisory by the FreeBSD security team might have been a bit overblown, but I understand and also fully support their better safe than sorry approach.

And last I also have a track record of 30 years of giving back to the FreeBSD project, and the OPNsense project more recently. Code, advocacy, donations, support, hosted two EuroBSDCons ...

If you want to chat about this over a beer or two - Dublin in September ;)

Kind regards,
Patrick
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

QuoteQuote

    Leave the IT space and go do something else.

Full support, such comments are neither helpful nor serve any issue for the community. Hoped it would go uncommented.

The people aware of the shortcommings broadly accepted in everday life of "pros" should not leave the profession, but have more responsibility in decission making for further hard- and software security. The next few years will be a hard time for security on a global scale...
kind regards
chemlud
____
"The price of reliability is the pursuit of the utmost simplicity."
C.A.R. Hoare

felix eichhorns premium katzenfutter mit der extraportion energie

A router is not a switch - A router is not a switch - A router is not a switch - A rou....

I bought 3 years of Business license, and intend to buy 3 more when that runs out. Also going to try and buy some hardware in the next 2 years, so not exactly a free-loader.

I am very grateful to be using the Community edition, and I deeply appreciate the forums.
Thank you to the devs and all who offer support in whatever form they can afford.
AppNeta m50 8GB
DEC690

*Nothing takes 5 minutes.*