|
|
|
|
|
by TacticalCoder
42 days ago
|
|
> For example, it might get combined with another exploit that can achieve unprivileged access ... Yeah. TFA mentions datacenters in 330 cities. That's a lot of Linux boxen. And many of those have, by definition, ports opened to the big bad Internet. These Linux servers are running services. They answer to ping, for a start. I even heard some are running DNS servers. Remote local exploits are a thing. What does CloudFlare prefer: that when the next remote local exploit surface all their fleet is one copy.fail away from privilege escalation to root or that they get the time (seen that they obviously have quite advanced detection measures in place) to detect the intruder before it gains root everywhere? It's Linux. It's datacenters in 330 cities. Linux powers the world and that's how things works. I, for one, I'm glad to own CloudFlare stocks since right after the 2022 crash and, for two, I'm happy they don't let their huge fleet of Linux servers with a non-patched exploit. |
|
I'm asking because I don't think they have such an exposure.