Re: Retiring lpr and lpd

Rick Macklem <[email protected]> Thu, 26 Feb 2026 14:29:35 -0800
Newsgroups gmane.os.freebsd.architechture
Message-ID <CAM5tNy4yZRk0+8DQFJBHCAkDG+h_MAPjgiAhFK3fXFpOw-Ppnw@mail.gmail.com>
On Thu, Feb 26, 2026 at 10:37=E2=80=AFAM Marco Moock <[email protected]> wrote:
>
> Am 26.02.2026 um 06:57:55 Uhr schrieb Rick Macklem:
>
> > I disagree. As Julian noted, some sort of warning w.r.t. known
> > security vulnerabilities is sufficient, I think.
>
> I have serious doubt that this is sufficient.
> The normal way is to fix them - or remove such software if it is
> abandoned. People can still get the code and install it, but it
> shouldn't be part of a default installation.
If I followed this edict, I would only allow Kerberized NFS and
NFS over TLS by default. Since 99.99999% of NFS mounts do
not do the above, I think there would be some pushback.
(The "bug" is in the original NFS design, using an RPC non-authentication
mechanism called AUTH_SYS.)

>
> > Security, like safety, is not an absolute. It requires a user/sysadmin
> > to evaluate the risks and make an informed decision on what to run
> > and how to do it.
>
> If a software has serious bugs that let remote users exploit them, it
> can only be used in an environment where only trusted machines and
> users can act.
Yes. Which is exactly what almost all NFS users do, using exports(5)
plus firewalls, etc.

rick

>
> --
> kind regards
> Marco
>
> Send unsolicited bulk mail to [email protected]