4 ms·
Wasn't the recent liblzma attack already exploiting the fact that systemd has its hands in pretty much everything? Wouldn't this expand further the attack surfa
by Iridescent_ 2y ago
Wasn't the recent liblzma attack already exploiting the fact that systemd has its hands in pretty much everything? Wouldn't this expand further the attack surface of systemd and the systems that connect with it?
- viraptor 2y agoThat's not a great summary of lzma. It was systems adding custom patch to ssh which used a systemd-related library which it didn't really need in the first place. It's a stack of issues that don't have much to do with systemd itself really. But re. expanding the attack surface - unlikely. Systemd's primary purpose is to start processes with the right environment / permissions. systemd-run/run0 basically give you the tool to invoke that functionality with a terminal attached to it. That's smaller scope of extra code than sudo/doas deal with.
- metta2uall 2y agoIsn't it a fault of systemd that libsystemd had a dependency on libxz? (because it implements too many things). It should have been possible to add the notification functionality using a tiny libsystemd-notify.
- viraptor 2y agoIt's not a fault. They needed xz for some functionality and didn't want to split that library into multiple pieces. That's just a choice. But either way, you could always do notification in a few lines yourself (probably as many as you needed to link that library in the first place). I've done multiple 3-line "implementations" in Python and Ruby in the past and never linked it for example.
- exe34 2y agoI'm surprised he hasn't started writing his own kernel by now.
- jbverschoor 2y agosystemd operates the system :-)
- SixDouble5321 2y agoI think this is bang on. Let's give it more surface area :/
- deleted 2y ago[deleted]