Update SSH Compression recommendation to reflect modern OpenSSH behavior

OpenSSH moved to delayed (post-authentication) compression by default
in 6.7, and removed pre-authentication compression support entirely in
7.4 (2016). The compression-oracle attack surface that motivated the
original `Compression no` recommendation no longer exists on any
currently supported OpenSSH version, so `Compression yes` is safe.

Fixes #117
This commit is contained in:
harshvasudeva committed 2026-08-10 21:18:13 +05:30
1 parent 21492c2507
commit aa9160adc9
1 file changed
+5 -1
+5 -1
View File
@@ -573,7 +573,11 @@ SSH is a door into your server. This is especially true if you are opening ports
# verify hostname matches IP
UseDNS yes
Compression no
# OpenSSH only supports delayed (post-authentication) compression since
# 6.7, and removed pre-auth compression support entirely in 7.4 (2016),
# so the old compression-oracle attack surface this setting guarded
# against no longer exists on any currently supported OpenSSH version
Compression yes
# TCP keepalive is spoofable (runs outside the encrypted channel)
# Use ClientAlive instead (runs inside the encrypted channel)