@aescling :psyduck: Do I need to do anything about it? If I've an SSH server and rsync?

@vaporeon_ i’m tempted to say not necessarily; most of the issues are with the client being able to be tricked by a misbehaving server (or proxy)

@aescling Ah, OK, so if I only regularly rsync between my own computers, then things are fine, even if one of those computers and its sshd is exposed to the global Internet?

@vaporeon_ you can get the server to leak purrivate info like environment variables, but if you’re only running the dæmon behind SSH then you have way bigger purroblems if somebody is successfully taking advantage of that

Sign in to participate in the conversation
📟🐱 GlitchCat

A small, community‐oriented Mastodon‐compatible Fediverse (GlitchSoc) instance managed as a joint venture between the cat and KIBI families.