Tatu Ylönen: A Password Theft Leads to SSH
Every time an administrator types ssh and a password prompt comes back encrypted, they're using a tool a Finnish graduate student wrote in three months because somebody stole his university's passwords.
Tatu Ylönen's Secure Shell replaced telnet and rlogin, the plaintext remote-login tools that'd run the internet since the 1970s, and it did so almost overnight. Today SSH is on every Linux server, every Mac, every router and every cloud, and port 22 is the most famous number in system administration.
Ylönen got the port by asking nicely. What he built with it became a company, a standard and, through a fork he didn't control, the most widely deployed security software on earth.
Tatu Ylönen at a Glance
- Ylönen studied at Helsinki University of Technology, finishing a master's degree in 1992 and a licentiate in 1994.
- In spring 1995, a password sniffer was discovered on a server on the university's backbone with thousands of usernames and passwords in its database. Ylönen decided to write a secure replacement for the tools that'd leaked them.
- He emailed IANA on July 10, 1995, asking for port 22. It was assigned the next day, and he released ssh 1.0.0 on July 12.
- In December 1995 he founded SSH Communications Security to support the protocol commercially. Within five years it had 190 employees and $20 million in sales, and in 2000 it listed on the Helsinki stock exchange.
- The OpenBSD team forked his last free release, 1.2.12, in September 1999. OpenSSH shipped that December and went on to run most of the world's servers.
- Ylönen co-authored the IETF standards for SSH, RFCs 4251 through 4254, published in January 2006.
- He was the principal author of NIST's 2015 guidance on SSH key management, after years of warning that enterprises had lost track of their keys.
- He's served as the company's CEO, CTO and chief innovation officer at different times. He holds 59 US patents and now spends his research time on computational linguistics.
The Life of Tatu Ylönen
Ylönen's Early Years
Tatu Ylönen grew up in Finland and studied at Helsinki University of Technology, the engineering school in Espoo that's since become part of Aalto University. He completed his master's degree in 1992 and a licentiate, the Finnish degree between a master's and a doctorate, in 1994.
By 1995 he was a researcher at the university, which, like every university on the early internet, ran a network full of Unix machines that people logged into from anywhere using telnet and rlogin.
Those tools sent everything in the clear. Every username, every password and every command crossed the wire as readable text, and anyone who could listen on the network could collect them.
The Sniffer on the Backbone
In the spring of 1995, somebody did exactly that. A password sniffer was found running on a server connected directly to the university's backbone, and by the time it was discovered its database held thousands of usernames and passwords.
Ylönen was a victim too. He also recognized the problem wasn't that one server but the design of every remote-login tool in use: there was no way to log in across the internet without handing your password to anyone in between.
So he started studying cryptography and built the tool he wanted to use himself. It combined public-key authentication of the server, automatic encryption of the whole session and integrity checks on the data, and it could carry X11 windows and other TCP connections through the same tunnel.
Three months after the sniffer was found, it was done.
Port 22
Ylönen designed SSH to replace both telnet, which lived on port 23, and FTP, on port 21. Port 22 was sitting unassigned between them, and he liked the symbolism.
On July 10, 1995, he emailed IANA, the body that hands out port numbers, explaining the protocol and adding that he was already using 22 in beta testing: "It would be great if this number could be used." Joyce K. Reynolds replied the next day: "We have assigned port number 22 to ssh, with you as the point of contact."
On July 12, 1995, at 5:23 in the afternoon, he announced ssh 1.0.0 to his beta testers. Twenty-eight minutes later he posted it to the cypherpunks mailing list, and it was public.
He gave it away. The source code was free to use, and the user base grew fast enough that supporting it became a full-time problem.
From Freeware to a Company
In December 1995, Ylönen founded SSH Communications Security to provide commercial support and development for the protocol. The following summer he presented SSH at the Sixth USENIX Security Symposium in a paper that remains the standard academic citation for the tool.
The timing was good. The web was commercializing, companies were connecting their networks to the internet, and the old plaintext tools suddenly looked reckless. SSH became the default way to administer a Unix server remotely.
Ylönen grew the company to $20 million in annual sales and 190 employees in five years, and in 2000 he took it public on the Helsinki stock exchange. Over the years he's run it as CEO, served as its CTO and chief innovation officer, and stepped back to the title he holds now, Senior SSH Fellow.
The Fork
Commercial success came with a change in licensing. Each new release of ssh carried more restrictions than the last, and by 1999 the current versions were no longer free software in the way the first one had been.
The last version free enough to reuse was 1.2.12. Early in 1999 a Swedish developer, Björn Grönvall, dug it up and started fixing bugs under the name OSSH. That September the OpenBSD team, less than two months from a release deadline, forked OSSH and set to work.
OpenSSH 1.2.2 shipped with OpenBSD 2.6 on December 1, 1999. It was free, it was aggressively audited, and within a few years it was the SSH on nearly every Linux distribution, every Mac and eventually Windows.
Ylönen's company kept selling its own implementation to enterprises, and still does. But the protocol he designed reached the world mostly through code he didn't write.
Making It a Standard
The second version of the protocol, SSH-2, fixed design weaknesses in the original and was taken to the Internet Engineering Task Force for standardization. The process took years.
In January 2006 the IETF published RFC 4251, the SSH protocol architecture, with Ylönen as author and Cisco's Chris Lonvick as editor, alongside RFCs 4252, 4253 and 4254 for authentication, transport and the connection layer. A protocol that'd started as one student's emergency fix was now an internet standard.
The Key Problem
Ylönen spent the 2010s warning about a problem his own invention had created. SSH keys never expire, they're trivial to generate, and nobody in a large organization was tracking them.
Large enterprises, he argued, had accumulated millions of keys over two decades, many granting root access to servers nobody remembered, and almost none of them audited. His company built a product line around finding and managing them.
In October 2015 the National Institute of Standards and Technology published NIST IR 7966, "Security of Interactive and Automated Access Management Using Secure Shell," with Ylönen as principal author. It was the first formal government guidance on SSH key management.
Ylönen Today
With 59 granted US patents and, by his own count, roughly 7,000 citations despite decades away from academic publishing, Ylönen has lately turned to a different problem: teaching computers to understand language.
His current projects include Kaikki.org, a machine-readable dictionary built from Wiktionary, and Wiktextract, the open-source tool that extracts it. He describes his medium-term interest as semantic parsing, pulling the meaning out of documents, and he still keeps a hand in SSH key management and post-quantum cryptography.
His company, meanwhile, says it serves more than 40 percent of the Fortune 500 and passed its thirtieth birthday in 2025.
Tatu Ylönen: The Quiet Protocol
Most security software announces itself. SSH is the opposite: it's so ubiquitous that nobody thinks about it, and so well designed that thirty years on, a 1995 decision about a port number is still the first thing a new server administrator learns.
Ylönen's story is also a lesson in what happens when you give something away. The fork he didn't control carried his protocol farther than his company ever could, and the standard that bears his name belongs to everyone.
He answered a password thief with a piece of software. The thief is forgotten. The software runs the world.
QUOTE:
"Amateurs hack systems, professionals hack people."