[ home / rules / faq ] [ overboard / sfw / alt ] [ leftypol / siberia / edu / hobby / tech / games / anime / music / draw / AKM ] [ meta / roulette ] [ cytube / wiki / git ] [ GET / ref / marx / booru / zine ]

/tech/ - Technology

"Technology reveals the active relation of man to nature" - Karl Marx
Password (For file deletion.)

Join our Matrix Chat <=> IRC: #leftypol on Rizon

File: 1714627731407.png (9.19 KB, 869x163, 1714581476442124.png)


Bravo Poettering, he did it again!!


File: 1714629231634-0.gif (3.99 MB, 426x284, systemd.gif)

File: 1714629231634-1.jpeg (252.48 KB, 1000x667, smug_lennart.jpeg)

I'm in awe of this lad


Who is this Poettering guy? Where did he come from? How did he come to be in such a influential position that he can force software down the throats of the basically the entire world?


He used to work at Red Hat.


systemd don't code something s6 figured out 10 years ago into pid 1 challenge IMPOSSIBLE https://skarnet.org/software/s6/s6-sudo.html




And he's now working for Microsoft. A true wrecker.


don't care still using doas on gentoo with openrc
porky will never force me to use systemd


reminder that the ssh exploit only affected systemd distros lol


Yeah, can't believe someone would develop an exploit that targets one of the most used pieces of software. Completely unheard of.


Newer versions of libsystemd don't use libxz anymore. This shows the devs are aware it is being used in security-sensitive contexts like sshd, but what they're doing amounts to polishing a turd. Libsystemd was never conceived to be used in that way.

The exploit was ultimately made possible by the actions of the major systemd distros. Despite the ubiquity of systemd, upstream openssh didn't deem it necessary to include the functionality for a good reason. As opposed to something like qmail, sshd is a single binary where a line of insecure code can compromise the whole program and all systemd related functionality was patched in by distro maintainers.

As far as i can see the dependency was added in 2022 to support the systemd notification protocol for socket activation:
>As of version 1:9.0p1-1ubuntu1 of openssh-server in Kinetic Kudu (Ubuntu 22.10), OpenSSH in Ubuntu is configured by default to use systemd socket activation. This means that sshd will not be started until an incoming connection request is received. This has been done to reduce the memory consumed by Ubuntu Server instances by default, which is of particular interest with Ubuntu running in VMs or LXD containers: by not running sshd when it is not used, we save at least 3MiB of memory in each instance, representing a savings of roughly 5% on an idle, pristine kinetic container.
Imagine adding a kludgy inetd because your defaults suck and users can't or won't pass 'systemctl disable sshd' to the system. Leaving readily accessible ssh daemons on every ubuntu system is an just waiting for an exploit like this to happen and maim every inattentive sysadmin in the process.


keep defending that ring 0 and pid 1 piece of shit faggot


right click -> run as administrator >>>>>> sudo


Not my fault that people only bother to find exploits for the only relevant* init system for linux (⁠ ⁠´⁠◡⁠‿⁠ゝ⁠◡⁠`⁠)
openrc do have its niche through alpine, though


OpenRC is the only init system that doesn't outright suck outside of systemd to my knowledge


under which criteria are systemDbusabuseD and sysvinit 2: electric boogalo the only inits that dont suck? alpine has been preparing to switch to s6 for the last few years fyi.


Runit is good.

Unique IPs: 9

[Return][Go to top] [Catalog] | [Home][Post a Reply]
Delete Post [ ]
[ home / rules / faq ] [ overboard / sfw / alt ] [ leftypol / siberia / edu / hobby / tech / games / anime / music / draw / AKM ] [ meta / roulette ] [ cytube / wiki / git ] [ GET / ref / marx / booru / zine ]