Re: sshd dependancy to systemd and attack surface

2024-03-30 Thread Colin Watson
On Sat, Mar 30, 2024 at 12:46:51PM +0100, Marc SCHAEFER wrote: > sshd has a dependancy to systemd, and thus includes a lot of libraries, > which augments its attack surface. libsystemd, not systemd. > The recent xz-utils issue [1] has lead to this post by someone suggesting > (with a patch,

sshd dependancy to systemd and attack surface

2024-03-30 Thread Marc SCHAEFER
Hello, sshd has a dependancy to systemd, and thus includes a lot of libraries, which augments its attack surface. The recent xz-utils issue [1] has lead to this post by someone suggesting (with a patch, apparently) to confine the sshd -> systemd dependancy in a subprocess [2]. Maybe you want to