Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <CAH8yC8kJ1VST96SB9=v2DC4djfa-NfTBN1dL29ZuOFbVGzOF2w@mail.gmail.com>
Date: Mon, 12 Oct 2020 16:51:11 -0400
From: Jeffrey Walton <noloader@...il.com>
To: oss-security@...ts.openwall.com
Subject: Re: Debian FEATURE: /home/loser is with permissions
 755, default umask 0022

On Mon, Oct 12, 2020 at 4:32 PM Kurt H Maier <khm@...ops.net> wrote:
>
> On Mon, Oct 12, 2020 at 09:41:39PM +0200, Solar Designer wrote:
> > I also think the defaults should be changed, and not only on Debian.
>
> This is just kicking the can down the road.  X years ago people
> complained about oppressive defaults.  X years from now these defaults
> will also be insufficient.   We could save a lot of treadmill labor
> dollars by just admitting that global filesystem namespaces are a
> mistake, but the sunk cost fallacy is preventing this.  It's the same
> story as SETUID all over again.

Maybe it's time to take a more defensive posture and guide a user
through the setup if they wish. Nowadays you've got those
systemd-triggered first-time logon GUI wizards that could include a
step to setup file sharing, like making /home/loser/www available to
other users.

The defensive posture should keep security conscious folks happy, and
the setup wizard will keep promiscuous users happy.

Jeff

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.