@JulianOliver @clacke I am fortunate enough to have a limited number of very paranoid colleagues who could theoretically have such issues and we work to reduce the attack surface, e.g. no root login, no passwordless escalation (doas/sudo) by users who can log in, idle logouts, and we avoid issues with X and lockscreens by not having X (or any other GUI) installed.