| ▲ | notpushkin 16 hours ago | |||||||
fwknop is a bit lower risk though. If all an attacker can do is open a port, they’ll still have to exploit OpenSSH. | ||||||||
| ▲ | akshayrajeshwar 16 hours ago | parent [-] | |||||||
fwknop's default is to run as root, so there's that. Support for separation of privileges is still pending since 2013 (https://github.com/mrash/fwknop/issues/32) | ||||||||
| ||||||||