hn.today

OpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One

zbruceli.org21 points8 comments
Screenshot of OpenSSH Ships on Every Mac, Linux Server and Windows. Its Creator Trusts No One

A long profile traces how a tiny timing anomaly stopped a near‑catastrophic supply‑chain backdoor aimed at OpenSSH and how that near‑miss underscores a single engineer’s influence over global server security. An attacker slipped malicious code into liblzma and relied on a dependency chain - systemd pulling in liblzma into SSH daemons - to activate a private‑key backdoor once distributions shipped new releases. A half‑second CPU delay noticed by a Microsoft engineer led to disclosure and rapid rollbacks across Linux distributions. OpenBSD escaped the blast radius because it never adopted systemd and had long enforced runtime restraints (pledge and unveil) and minimal default services, design choices that abruptly limited the attack’s reach.

The profile follows Theo de Raadt from apartheid South Africa to Calgary, through co‑founding NetBSD, being expelled for abrasive conduct, and forking OpenBSD in 1995 to enforce a doctrine of proactive security. He built regular releases, relentless code audits, and conservative defaults so that code is assumed hostile and programs die fast when they misbehave. Personal feuds, a lost DARPA grant and outspoken denunciations of other open‑source figures accompany a philosophy of “trust no one” that produced OpenSSH and many of the defensive practices now running on Macs, Linux servers and Windows. The result is engineering shaped by paranoia that many administrators rely on daily.

Read on zbruceli.org8 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.