{"id":11450,"date":"2025-04-09T10:12:06","date_gmt":"2025-04-09T17:12:06","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=11450"},"modified":"2025-04-09T10:12:06","modified_gmt":"2025-04-09T17:12:06","slug":"openssh-10-0-released-to-better-fend-off-attacks-by-quantum-computers","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2025\/04\/09\/openssh-10-0-released-to-better-fend-off-attacks-by-quantum-computers\/","title":{"rendered":"OpenSSH 10.0 Released To Better Fend Off Attacks By Quantum Computers"},"content":{"rendered":"\n<p>They&#8217;re hyping up quantum computers with it possibly being the next hype train after AI systems, but it&#8217;s still nice to know that they&#8217;re working on future proofing cryptography for the when dividing large numbers becomes much faster and a threat to current systems. <\/p>\n\n\n\n<p><a href=\"https:\/\/www.phoronix.com\/news\/OpenSSH-10.0-Released\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/www.phoronix.com\/news\/OpenSSH-10.0-Released<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_f28bf38a-c6b7-40fc-af59-f0e26babea79\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<p>By Michael Larabel<\/p>\n\n\n\n<figure class=\"wp-block-image alignright is-resized\"><img decoding=\"async\" src=\"https:\/\/www.phoronix.com\/assets\/categories\/freesoftware.webp\" alt=\"FREE SOFTWARE\" style=\"width:333px;height:auto\"\/><\/figure>\n\n\n\n<p>OpenSSH 10.0 is now available for this widely-used SSH client\/server implementation. There are a number of changes to find with OpenSSH 10.0 including better protections against possible attacks by future quantum computers.<br><br>OpenSSH 10.0 drops support for the weak DSA signature algorithm that had been deprecated already for the past decade. The SSH daemon (SSHD) also removes code responsible for the user-authentication phase of the protocol to a new &#8220;sshd-auth&#8221; binary to better segregate the pre-authentication attack surface.<br><br>OpenSSH 10.0 on the security side also fixes the &#8220;DisableForwarding&#8221; for X11 forwarding as it turns out it was failing to disable X11 forwarding and agent forwarding as documented.<br><br>For better protections in a quantum computing world, OpenSSH 10.0 now uses the hybrid post-quantum algorithm mlkem768x25519-sha256 by default for key agreement. The mlkem768x25519-sha256 algorithm is currently deemed safe against possible attacks by quantum computers and is considered faster than the prior default.<br><br>OpenSSH 10.0 also adds a work-in-progress tool for verifying FIDO attestation blobs. The experimental tool in OpenSSH 10.0 can be found under <em>regress\/misc\/ssh-verify-attestation<\/em> for experimenting but not installed by default.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter\"><img decoding=\"async\" src=\"https:\/\/www.phoronix.net\/image.php?id=2025&amp;image=openssh\" alt=\"OpenSSH logo\"\/><\/figure>\n\n\n\n<p>More details on the many changes to find with today&#8217;s OpenSSH 10.0 release via the <a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2025\/04\/09\/1\">mailing list announcement<\/a> and downloads via <a href=\"https:\/\/www.openssh.com\/\">OpenSSH.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>They&#8217;re hyping up quantum computers with it possibly being the next hype train after AI systems, but it&#8217;s still nice to know that they&#8217;re working on future proofing cryptography for the when dividing large numbers becomes much faster and a threat to current systems. https:\/\/www.phoronix.com\/news\/OpenSSH-10.0-Released By Michael Larabel OpenSSH 10.0 is now available for this [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-11450","post","type-post","status-publish","format-standard","hentry","category-tech"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/11450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=11450"}],"version-history":[{"count":1,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/11450\/revisions"}],"predecessor-version":[{"id":11451,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/11450\/revisions\/11451"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=11450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=11450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=11450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}