Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

vanilla upstream OpenSSH DOESN'T depend on xz

that's what i believed as well, but i didn't take time to verify. and i didn't know about the details. thanks. as you describe it ssh still doesn't depend on xz (and why would it?) so part of the problem here is software architecture.

how is it possible that a seemingly unrelated dependency somewhere within systemd can affect and be exploited through ssh directly?

shouldn't it be possible to keep that separate?

doesn't openssh itself already implement some form of privilege separation?

how does software architecture here and in general need to change to prevent things like this?

i am sure somewhere these questions are already being discussed. i'd appreciate any pointers.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: