Subtitle: Qualys finds two worrying bugs in OpenSSH

When I checked my personal rigs Debian had already released the patches and my home server had already auto updated itself.

  • demesisx@infosec.pub
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    7
    ·
    4 days ago

    Hot take: Might be wise to adopt the security by obscurity model and go with an OS that is hardened (ideally, a formally verified microkernel like sel4) or runs in a custom VM/container with almost zero attack surface area.