If you have SSH open from outside, you're doing something wrong.
And suddenly your VPN protocol has a CVE. And then people are like "Oh no you are not supposed to open a VPN to the outside." xDAnything exposed can be potentially attacked. And if the attack surface is known, it will be mitigated.E.G.:https://en.m.wikipedia.org/wiki/Anti-replay
VPN is not fundamentally more secure than SSH. It's one of the most secure protocols and products existing.
A VPN might expose a root RCE with more or less the same probability as SSH.
Layers <3https://forum.opnsense.org/index.php?topic=40654.msg199395#msg199395But Layers mean nothing if the most front facing technology can be exploited to give remote code execution with root access.
Well. By that logic, lets not use computers at all. Lets get back to stone age.
Quote from: alex303 on July 02, 2024, 10:10:11 pmWell. By that logic, lets not use computers at all. Lets get back to stone age. Can we please go back, my life would be SO much more simple!