The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > Special Forums > Security
Google UNIX.COM
Home Forums Register Rules & FAQ Members List Arcade Search Today's Posts Mark Forums Read


Security Anything involving computer security goes here.


Other UNIX.COM Threads You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
free vs commercial Unix Verbose Bob UNIX for Dummies Questions & Answers 15 04-01-2004 01:36 PM

Reply
 
Submit Tools LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 12-11-2006
Registered User
 

Join Date: Sep 2002
Posts: 67
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
commercial SSH vs. OpenSSH

I'm not sure if this is appropriate for the forum, but I figured it was security related, so here goes...

I'm writing an anlaysis for my group about moving some of the old internet protocols (rsh, rlogin, etc...) to the SSH suite of tools. An outside security group recommended a commercial version of SSH (Tectia), but I'm not sure that it's worth paying for. I have lots of previous experience with OpenSSH, and I was wondering if the commercial version offered anything more than the open-source version. I understand that the open-source version does not use patented algorithms. Am I losing any level of security by using the open-source version over the commercial version?

Any info would be greatly appreciated!!
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 12-11-2006
Registered User
 

Join Date: Aug 2005
Location: Saskatchewan
Posts: 923
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
Given they're implementing the same algorithms(DES, etc) how different can they be? Seems like open-source-paranoia to me, the outdated notion that actively updated open source is wide-open to hackers while slower-updated closed source is invulnerable.
Reply With Quote
  #3 (permalink)  
Old 12-11-2006
Registered User
 

Join Date: Nov 2003
Location: Minnesota
Posts: 379
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
IMHO there is no valid reason to use commercial SSH instead of OpenSSH. I've worked at several companies which provide web services and all used OpenSSH. If there were any real security issues with it we never could have done that.
Reply With Quote
  #4 (permalink)  
Old 12-12-2006
sysgate's Avatar
Unix based
 

Join Date: Nov 2006
Location: /root
Posts: 1,069
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
Only old versions of OpenSSH has some exploits available, but still, not so dangerous.
However, some companies prefer the "enterprise" approach rather than open-source.
Reply With Quote
  #5 (permalink)  
Old 12-15-2006
System Shock's Avatar
Registered User
 

Join Date: May 2006
Location: Tau Ceti V
Posts: 361
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiReddit! Stumble this Post!Spurl this Post!
The outside security company says that because of liability.

Something goes wrong with an open source app, there's no one to call for help, and there's no one liable other than yourself, yet, the security company who told you it was ok to use an open source app may become liable.
Reply With Quote
Google UNIX.COM
Reply



Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 11:26 PM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger

Search Engine Optimization by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102