From aa9160adc96fb1d51ba5f692dce97b93dbe0bec5 Mon Sep 17 00:00:00 2001 From: harshvasudeva <19649313+harshvasudeva@users.noreply.github.com> Date: Mon, 10 Aug 2026 21:18:13 +0530 Subject: [PATCH] Update SSH Compression recommendation to reflect modern OpenSSH behavior OpenSSH moved to delayed (post-authentication) compression by default in 6.7, and removed pre-authentication compression support entirely in 7.4 (2016). The compression-oracle attack surface that motivated the original `Compression no` recommendation no longer exists on any currently supported OpenSSH version, so `Compression yes` is safe. Fixes #117 --- README.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 5e9de51..2ffdd8f 100644 --- a/README.md +++ b/README.md @@ -573,7 +573,11 @@ SSH is a door into your server. This is especially true if you are opening ports # verify hostname matches IP UseDNS yes - Compression no + # OpenSSH only supports delayed (post-authentication) compression since + # 6.7, and removed pre-auth compression support entirely in 7.4 (2016), + # so the old compression-oracle attack surface this setting guarded + # against no longer exists on any currently supported OpenSSH version + Compression yes # TCP keepalive is spoofable (runs outside the encrypted channel) # Use ClientAlive instead (runs inside the encrypted channel)