4 ms·
A tangent: are VPNs other than WireGuard less likely to have vulns compared to SSH? Seems the same to me (or worse for OpenVPN a few years ago)
by Quiark 6y ago
A tangent: are VPNs other than WireGuard less likely to have vulns compared to SSH? Seems the same to me (or worse for OpenVPN a few years ago)
- wglb 6y agoOne crude first-order comparison is to look at the relative size of the code. More code is more likely to have more vulnerabilities, to a first-order BOEC metric.
- tptacek 6y agoYou're asking for my opinion, and that's all I can relate, but here's my ranked ordering of things likely to have RCE vulnerabilities, from least to most secure: * A Java, Python, or Ruby app server * OpenVPN * Stock nginx ----- starts to get really unlikely right here ---- * OpenSSH * The Linux IP stack * WireGuard