Linux devices are under attack by a never-before-seen worm
arstechnica.com
arstechnica.com
This doesn't seem serious at all, nor difficult to detect. Am I missing something?
The point of ssh is to use the keys for authentication. Having the ssh server permit password login is a back-compatible legacy from the telnet days and has been functionally obsolete for decades.
This doesn't sound particularly new or concerning. Right?
When you can waste an exploit like this on installing crypto
Whatever NSA and other advanced nation states have is magnitudes next level.
NSO Group sells some advanced stuff, but again what Israel keeps behind locked doors again have to be magnitudes next level.
https://github.com/akamai/akamai-security-research/blob/main...
My implication was that if you've managed to set up qubes so wrong that you would be affected by this, there's a good chance that you've made other massive mistakes too, making your qubes usage meaningless.
That being said. Qubes is an excellent piece of software and you are correct in your statements.