Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <87v9flhhj5.fsf@canidae.wired.pri>
Date: Thu, 08 Oct 2020 08:07:10 +1100
From: Brian May <brian@...uxpenguins.xyz>
To: oss-security@...ts.openwall.com
Subject: Re: Debian FEATURE: /home/loser is with permissions 755, default umask 0022

Jeremy Stanley <fungi@...goth.org> writes:

> As a long-time Debian user myself, I agree that this default is
> showing its age, and can represent a risk for operators who overlook
> it.

Yes, I agree the default should be changed.

Just note that there is a reasonable amount of software install
instructions that assume umask is 022 and will install software with
unusable permissions if it is not.

Perhaps the worst example I can think of is Docker image builds.
COPY/ADD will install the files in the Docker image with their current
permissions with no way to override. So all the files inside the image
unreadable for everyone except by root. If you want to run stuff inside
the Docker image as non-root (which is recommended) you either have to
fix the permissions first or add a RUN command to fix the permissions -
which can be slow and the layer generated can be large (due to the
inefficient way layers are represented in Docker).
-- 
Brian May <brian@...uxpenguins.xyz>
https://linuxpenguins.xyz/brian/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.