2 ms·
Code that is never normally used can sometimes still be gotten to run by an attacker, and therefore can still be a security risk.
by advisedwang 5mo ago
Code that is never normally used can sometimes still be gotten to run by an attacker, and therefore can still be a security risk.
- M95D 5mo agoBut that code would have to be selected in menuconfig, compiled, and the module loaded. I assume that nobody does that for bus mice, and even if someone, by mistake, selects one of the drivers, that's 1 machine in a billion. Who would target that? Same argument for any retro-tech. What hacker would spend hours/days to hack my bare-metal DOS box running Arachne + a packet driver just to mine bitcoins on a K6-2 for a couple of hours until I turn it off from the AT power switch (not button).
- advisedwang 5mo agoGood point. I guess I have this issue in the back of my mind [1], which was widely shipped with ffmpeg despite being basically never needed. [1] https://x.com/FFmpeg/status/1983949866725437791 https://x.com/FFmpeg/status/1983949866725437791
- Someone1234 5mo agoFrom my understanding, that isn't how drivers in Linux work. Nearly no kernels will have that code compiled into them because kconfig won't call for it. It is "opt-in", and it is so niche few Distros would have done so. Linux only ships with a tiny sub-set of the drivers in the source tree.