(01-07-2021, 10:33 PM)ryo Wrote: Not sure what this even has to do with using SSH safely?
Nothing in particular. My point is that a port is exposed to the internet and a deamon could potentially be compromised. And I want to be safe of Kernel exploits in the likes of dirty_COW. So I want to have a system that receives good support and regular Kernel updates:
(01-07-2021, 09:12 AM)kuleszdl Wrote: @kwinz If you don't need USB3 support you can also go with official Debian now - either the unstable/testing distribution or the stable distribution (buster) with the unstable kernel. Personally, I would discourage keeping keeping the SSH port exposed to the Internet if you are running an outdated kernel, even if the ssh server itself is regularly updated. The issue here is that there sometimes are also vulnerabilities in the TCP/IP stack of the kernel which could be exploited.