Re: When SSH standards noncompliance is a "feature"

Peter Gutmann <[email protected]> Thu, 10 Jun 2021 16:35:12 +0000
Newsgroups gmane.ietf.secsh
Message-ID <SY4PR01MB625165FD641CEE486344E256EE359@SY4PR01MB6251.ausprd01.prod.outlook.com>
Jeffrey T. Hutzelman <[email protected]> writes:

>About the only thing this does is prevent security scanning software from
>reporting the apparent presence of a vulnerable version.

Yup, and that's exactly the reason for doing it: You don't need to fix a vuln
when the scanner can't tell anyone you have it.

As Raymond Chen likes to say, "I bet somebody got a really nice bonus for that
feature".

Peter.