TLDRocket
Sign in

OpenSSH 10.6 deliberately breaks two features in the name of security

The New Stack Amanda Caswell

OpenSSH 10.6 turns off one compression trick and bans $ and \ in some usernames. Both changes break edge cases on purpose so secrets and shells stay safer.

Based on reporting by The New Stack, Amanda Caswell — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

OpenSSH 10.6, released Tuesday, is one of those updates that makes life slightly less convenient because the maintainers decided the risk was worse than the hassle. It weakens SSH compression and rejects some command-line usernames that used to work. Both changes were known breakages when they shipped.

The bigger fix is in compression. OpenSSH used the LZ77 part of deflate to reuse repeated byte sequences, and it shared that compression history across multiplexed SSH channels. That was the opening Ruhr University Bochum researchers Fabian Bäumer and Marcus Brinkmann exploited in their paper, “Crossing the Streams: SSH Plaintext Recovery via a Common Compression Context in Multiplexed Channels.” If an attacker can inject chosen plaintext into one channel and observe encrypted traffic, they can sometimes tease secrets out of another channel in the same session.

The maintainers chose the blunt answer: remove the shared dictionary entirely. Huffman coding stays, so compression still exists, just less effectively. OpenSSH now says the Compression option will be weaker and recommends moving compression to the application layer, where it says it usually works better and avoids this specific leak. Most ordinary interactive sessions probably won’t notice much. Automated jobs pushing lots of compressible data over slow links are more likely to care.

The attack itself is in the same family as CRIME and BREACH, but the setup is narrower. OpenSSH leaves compression off by default, so this only matters when someone has turned it on. In the researchers’ lowest-noise tests, they recovered an eight-character secret drawn from a 26-character alphabet in a median of 276 guesses across 100 trials. In a noisier browser-based setup, that rose to about 27,600. The proof-of-concept work for all three scenarios was built with Claude Code, and the release also credits Chris Rohlf, working with Claude and Anthropic Research, with finding two other bugs fixed in 10.6.

The other breakage is more mundane but still nasty for automation. OpenSSH now blocks $ and \ in usernames passed on the command line, because those characters can get treated as shell syntax inside directives like ProxyCommand and Match exec. That does not apply when the username is set with the User directive in an SSH config file. A related bug was already tightened in 10.3, but this version closes the door harder for scripts and agents that build ssh commands from outside input.

My take — AI-written commentary, not fact-checked reporting

This is the right kind of annoying. SSH has spent years being the thing everyone trusts not to get clever in exactly the wrong place, so breaking a few edge cases beats preserving a footgun. The real story is how much AI-assisted research is now sitting on top of old protocol assumptions, and the old assumptions are losing.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.