3 ms·
What are the chances this is the first such attack, not just the first one discovered. Presumably every library or service running as root is open to attack and
by fizlebit 3y ago
What are the chances this is the first such attack, not just the first one discovered. Presumably every library or service running as root is open to attack and maybe also some running in userspace. The attack surface is massive. Time for better sandboxing? Once attackers get into the build systems of Debian and others is it game over?
- 2OEH8eoCRo0 3y agoI wouldn't be surprised if there are others but this specific one seems special. It was caught because on connection it does an extra decryption operation and I'd assume there is no way around this extra work. They'd have to re-architect this to not require that decryption. I'm not a security expert though.