Hacker News new | ask | show | jobs
by viraptor 1061 days ago
> How would this even be mitigated while preserving the (wacky) existing support for runtime-selected PKCS#11 provider libraries?

Put the pkcs11 libraries in a specific directory, configure only that directory, let users manually add others. Or stop using forwarding and configure ProxyJump where needed. (If that's the only use case you're interested in)