[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: openssh-server's default config is dangerous



Le quintidi 25 messidor, an CCXXIV, Don Armstrong a écrit :
> If a services default configuration is insecure, it should be fixed.
> File a bug.

If you think about it slightly more than two seconds, you will realize that
if the default configuration does ANYTHING, even something that is
completely harmless in 99.99% of the cases, then there will be some cases
where this is a serious issue, where the administrator really did not want
it to happen. Even if it is only 0.01% of the cases, that is still too many.

I am flabbergasted too see how many people oppose the obviously correct
solution to that kind of issue: have a global option "Start services after
installing? always / ask / never".

Attachment: signature.asc
Description: Digital signature


Reply to: