"
* We have seen a number of cases where a security bug identified
* by AI tools is subsequently independently discovered by a
* different researcher. This suggests that adversaries who do not
* report bugs to OSS projects are likely to be able to discover
* these bugs too. Given this, the OpenSSH team will, for now, be
* making more frequent releases to get bugfixes into users' hands
* more quickly rather than batching them until the next planned
* release."
> sshd(8): On OS X SDK >= 27, sandboxing is no longer supported as the API we depended upon has been removed and no obvious alternative provided.
https://github.com/openssh/openssh-portable/commit/d4b4c304a...
Deprecated since Mountain Lion. https://issuetracker.google.com/40474030
It’s what Apple experimented with before they came up with the current entitlements system.
So Apple's had 14 years to work with OpenSSH, and instead chose to break sandboxing?
They mention a donation link: https://www.openbsd.org/donations.html
I wonder what their funding is like.
" * We have seen a number of cases where a security bug identified * by AI tools is subsequently independently discovered by a * different researcher. This suggests that adversaries who do not * report bugs to OSS projects are likely to be able to discover * these bugs too. Given this, the OpenSSH team will, for now, be * making more frequent releases to get bugfixes into users' hands * more quickly rather than batching them until the next planned * release."
I think this is much healthier approach to AI reports than curl has. But I understand both sides.
Really glad to see the rate of security fixes speeding up.