4 ms·
I'm missing something. If the goal of revoking ssh access is to stop kernel devs being able to run arbitrary commands on kernel.org servers...surely you can't g
by jbert 15y ago
I'm missing something. If the goal of revoking ssh access is to stop kernel devs being able to run arbitrary commands on kernel.org servers...surely you can't give them permissions to set their own commit hooks?
If an attacker compromises a kernel dev, instead of using their ssh access to run cmds on kernel.org, they just use their hook access to run cmds on kernel.org.