You are viewing a single thread.
View all comments View context
2 points

It won’t be a security risk once it’s in use, IT across Germany will know within days of deployment. It will almost definitely be a modified version of some probably well known Linux.

permalink
report
parent
reply
1 point

No sense in giving an adversary info on the distro before it’s fully implemented though I imagine. (I would consider that a head-start even if they heavily modify a popular distro)

Giving the See👁️Aye advanced notice wouldn’t be smart, no matter how they wanted to play it.

It won’t be a security risk once it’s in use

I agree

permalink
report
parent
reply
0 points

I don’t think it really matters whether a potential adversary has a ‘head start’ all that much, security through obscurity doesn’t work super well when it’s going to be deployed to thousands of easily accessible devices anyway. It’d only just be a defense in depth, but even then meh. But it’s neither here nor there, they’ll do it whatever way they feel is best.

permalink
report
parent
reply
1 point

Basically all of social engineering is to get exactly what you’re talking about, a “head start”

Go to their LinkedIn: does the head engineer have MySQL version X on his skills, resume, job description, etc? Maybe somebody even endorsed them for it? “Wow they are THE best database administrator”

Now you know who you need to hack for their database access AND what zero days to research.

ANY info will be an attack vector

permalink
report
parent
reply

Technology

!technology@lemmy.ml

Create post

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

Community stats

  • 4K

    Monthly active users

  • 2.7K

    Posts

  • 44K

    Comments

Community moderators