Re: Retiring lpr and lpd
Rick Macklem <[email protected]> Thu, 26 Feb 2026 14:29:35 -0800
| Newsgroups | gmane.os.freebsd.architechture |
|---|---|
| Message-ID | <CAM5tNy4yZRk0+8DQFJBHCAkDG+h_MAPjgiAhFK3fXFpOw-Ppnw@mail.gmail.com> |
On Thu, Feb 26, 2026 at 10:37=E2=80=AFAM Marco Moock <[email protected]> wrote: > > Am 26.02.2026 um 06:57:55 Uhr schrieb Rick Macklem: > > > I disagree. As Julian noted, some sort of warning w.r.t. known > > security vulnerabilities is sufficient, I think. > > I have serious doubt that this is sufficient. > The normal way is to fix them - or remove such software if it is > abandoned. People can still get the code and install it, but it > shouldn't be part of a default installation. If I followed this edict, I would only allow Kerberized NFS and NFS over TLS by default. Since 99.99999% of NFS mounts do not do the above, I think there would be some pushback. (The "bug" is in the original NFS design, using an RPC non-authentication mechanism called AUTH_SYS.) > > > Security, like safety, is not an absolute. It requires a user/sysadmin > > to evaluate the risks and make an informed decision on what to run > > and how to do it. > > If a software has serious bugs that let remote users exploit them, it > can only be used in an environment where only trusted machines and > users can act. Yes. Which is exactly what almost all NFS users do, using exports(5) plus firewalls, etc. rick > > -- > kind regards > Marco > > Send unsolicited bulk mail to [email protected]