OpenSSH Splits Again: New Authentication Binary Unveiled
Quoting: OpenSSH Splits Again: New Authentication Binary Unveiled —
The ongoing effort to enhance OpenSSH security by splitting functionalities into separate binaries continues, with the latest development introducing a new binary, sshd-auth.
This change is a part of OpenBSD’s broader strategy to make the OpenSSH implementation even more secure and efficient.
Damien Miller, an OpenBSD developer, recently committed this new update, which aims to further segregate the sshd functionality by creating a dedicated binary for user authentication.
As stated in the commit message, the goal is straightforward: “Splitting this code into a separate binary ensures that the crucial pre-authentication attack surface has an entirely disjoint address space from the code used for the rest of the connection.“