| Your question was this: >So what’s the difference in risk of ssh software vulns and other software vulns? I proceeded to explain how large companies think about the issue and what their rationale is for not exposing SSH endpoints to the public internet. On the technical side, I compared SSH to WireGuard. For that comparison, the chattiness of their respective protocols was directly relevant. Likewise complexity: between two highly-audited pieces of software, the silent one that's vastly simpler tends to win from a security perspective. All of those points seem highly relevant to your question. >... but thats not going to make you correct in the original question. If you can elucidate what I said that was incorrect, I'm all ears. |
Edit: codebase of ssh/wireguard implementations, just to be clear