Visiting a random website is the normal use of HTTP. With SSH, there might be assumptions of connecting to a trusted server you have an account with and likely own. It's not very normal to ssh to a random server.
I don't know how you are using ssh, but most ssh servers that I have connected to in my life, and still do, I don't own. Some of them I barely trust.
When I said "own", I meant more in the sense of personally administering. It's like how you own a domain, but you're really renting it from a registrar. Rented hardware and VPSs count, as well as other servers/hosts you're responsible for.
Are we all pretending we have no empirical data on this? How many RCEs has there been in popular web browsers over the past two decades (dozens? hundreds?), compared to how many RCEs there has been in the OpenSSH client (perhaps we can make it one if we include xterm in that)?
3dedb728-3f77 · · focus · HN ↗
People understand that reverse hacking can happen when connecting to random ssh server, right?
bulbar · · focus · HN ↗
jolmg · · focus · HN ↗
teiferer · · focus · HN ↗
I don't know how you are using ssh, but most ssh servers that I have connected to in my life, and still do, I don't own. Some of them I barely trust.
QuantumNomad_ · · focus · HN ↗
hdgvhicv · · focus · HN ↗
jolmg · · focus · HN ↗
teiferer · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
[deleted] · · focus · HN ↗
[deleted]
singpolyma3 · · focus · HN ↗
xorcist · · focus · HN ↗
bulbar · · focus · HN ↗
Regarding empirical data, that would certainly be interesting, not sure if RCE is the only category one would look at in that case.