|
Message-ID: <20111002105457.GA5598@albatros> Date: Sun, 2 Oct 2011 14:54:57 +0400 From: Vasiliy Kulikov <segoon@...nwall.com> To: Guillaume Chazarain <guichaz@...il.com> Cc: Linus Torvalds <torvalds@...ux-foundation.org>, Linux Kernel Mailing List <linux-kernel@...r.kernel.org>, Balbir Singh <bsingharora@...il.com>, kernel-hardening@...ts.openwall.com Subject: Re: taskstats root only breaking iotop (cc'ed kernel-hardening) On Sun, Oct 02, 2011 at 12:22 +0200, Guillaume Chazarain wrote: > On Sun, Oct 2, 2011 at 2:20 AM, Linus Torvalds > <torvalds@...ux-foundation.org> wrote: > > So I don't see why you ask for it. What could possibly be a valid use-case? > > Right, kbyte granularity is enough. It is not enough. In some border cases an attacker may still learn private information given the counters with _arbitrary_ granularity: http://www.openwall.com/lists/oss-security/2011/06/29/9 > And that's consistent with > /proc/vmstat, which nobody is complaining about. <jumping with a raised hand>Me, me, it was me!</jumping with a raised hand> Seriously, most of procfs files were created with relaxed permissions in old days when nobody thought about such infoleaks. Now it is much harder to close all of them without breaking existing users. http://www.openwall.com/lists/kernel-hardening/2011/07/28/1 http://www.openwall.com/lists/kernel-hardening/2011/09/27/3 http://www.openwall.com/lists/kernel-hardening/2011/09/19/24 http://www.openwall.com/lists/kernel-hardening/2011/09/21/2 Thanks, -- Vasiliy Kulikov http://www.openwall.com - bringing security into open computing environments
Powered by blists - more mailing lists
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.