What is the danger in having a port exposed that can receive updates for time? Are there huge vulnerabilities in the ntpd? Seems like a pretty small attack surface to me.
actually... Is that port even open?!
This is polling a time server through NAT right? So the ports get negotiated. We're not listening, were asking. So I guess the danger would be that your time server of choice could be compromised, and then start sending out malicious packets that... confuse ntpd? Seems like were back where we started.
There was some stupid stuff in that article, twitter updates being perhaps the most colossal (and voice control coming in a neat second, web control @ 3). However, once you take flame decals off and remove the card in the spokes, this ceases to be the danger it once was.