4 ms·
Until formal verification becomes common, something the size of systemd is always going to have security bugs that intelligence agencies will know about before
by ofubd8kc 5y ago
Until formal verification becomes common, something the size of systemd is always going to have security bugs that intelligence agencies will know about before the rest of us. If you don't want North Koreans hacking your server you would do better to opt for non-systemd.
- zxzax 5y agoSure some people might know about bugs before others, and may seek to abuse that knowledge, but I don't think that is limited to intelligence agencies, and I don't think that has anything to do with the size of the project either. If you have some studies and data that goes over all the risk factors here, I'd love to see it. >If you don't want North Koreans hacking your server you would do better to opt for non-systemd. This seems to be fear-mongering and doesn't seem to follow at all from what you said either. There are a lot of other large projects used by the various Linux distributions, systemd is not out of the ordinary here. For an example of what you're looking at here, debian bullseye has 1.17 billion lines of code in total: https://sources.debian.org/stats/ https://sources.debian.org/stats/ Of course you would have to do a deeper dive to see just how much of that is expected to run as root or with CAP_SYS_ADMIN, or in kernelspace.