3 ms·
> If a zero-day drops in OpenSSH... Realistically, fwknop is more likely to have a vuln than OpenSHH. Last release was two years ago and the readme dates back
by akshayrajeshwar 2mo ago
> If a zero-day drops in OpenSSH...
Realistically, fwknop is more likely to have a vuln than OpenSHH. Last release was two years ago and the readme dates back twelve :/ Time will tell.
- mmh0000 2mo agoSeriously. If a zero-day drops in OpenSSH, it's quite literally the end of the world.
- notpushkin 2mo agofwknop is a bit lower risk though. If all an attacker can do is open a port, they’ll still have to exploit OpenSSH.
- akshayrajeshwar 2mo agofwknop's default is to run as root, so there's that. Support for separation of privileges is still pending since 2013 (https://github.com/mrash/fwknop/issues/32 https://github.com/mrash/fwknop/issues/32)
- notpushkin 2mo agoGood point, thanks.