Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <alpine.GSO.2.20.2010071604290.15793@scrappy.simplesystems.org>
Date: Wed, 7 Oct 2020 16:09:59 -0500 (CDT)
From: Bob Friesenhahn <bfriesen@...ple.dallas.tx.us>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: Debian FEATURE: /home/loser is with permissions
 755, default umask 0022

On Wed, 7 Oct 2020, Georgi Guninski wrote:

> https://lists.debian.org/debian-security/2020/10/msg00000.html
>
> ===
> /home/loser is with permissions 755, default umask 0022
>
> on multiuser machines this sucks much.

These are my preferred default settings for multiuser machines and is 
the historical default.  The settings can be changed when appropriate.

Ubuntu Linux (a Debian derivative) has changed the default.  However, 
we found that the Ubuntu default caused problems for us while building 
our software, and so we changed them back.

Users often need to share data.

There is a lesson to be learned that sensitive data and directories 
under a user's home directory may still need to have more strict 
permissions set by the applications which create them since the top of 
the user's home directory might allow sharing.

Bob
-- 
Bob Friesenhahn
bfriesen@...ple.dallas.tx.us, http://www.simplesystems.org/users/bfriesen/
GraphicsMagick Maintainer,    http://www.GraphicsMagick.org/
Public Key,     http://www.simplesystems.org/users/bfriesen/public-key.txt

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.