top | item 46287305

(no title)

harvie | 2 months ago

Also upstream is extremely well audited. That's a huge benefit i don't want to loose by using fork.

discuss

order

rapier1|2 months ago

I do want to say that HPN-SSH is also well audited; you can see the results of CI tests on the github. We also do fuzz testing, static analysis, extensive code reviews, and functionality testing. We build directly on top of OpenSSH and work with them when we can. We don't touch the authentication code and the parallel ciphers are built directly on top of OpenSSL.

I've been developing it for 20+ years and if you have any specific questions I'd be happy to answer them.

Bad_CRC|2 months ago

this, I'm not going to start using a random ssh fork with modified ciphers.

Zambyte|2 months ago

It may still be sensible if you only expose it to private networks.