RE: [EXTERNAL] Re: Using certificates and keys from a list

"'Michael Wojcik' via openssl-users" <[email protected]> Thu, 9 Apr 2026 13:23:51 +0000
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <CH3PPFBCC09965C790141D1358D53A2C770C0582@CH3PPFBCC09965C.namprd07.prod.outlook.com>
> From: 'Martin Bonner' via openssl-users <[email protected]>
> Sent: Thursday, 9 April, 2026 00:38

> If an attacker can=E2=80=99t get code execution inside your app, then why=
 bother dropping
> to the unprivileged user at all?

That threat model is too simplistic. There are potential vulnerabilities wh=
ich could result in an attacker having limited control over the application=
's behavior, insufficient to revert the effective UID but capable of taking=
 other actions. Your example of file I/O is an obvious one, but there are p=
lenty of others.

Changing the EUID is defense in depth.

That said, it's probably not the architecture I'd use; I prefer stronger se=
paration between privileged and non-privileged functions. But I don't know =
enough about the application and its use cases to define one more to my lik=
ing.

--
Michael Wojcik
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D
Rocket Software, Inc. and subsidiaries =E2=96=A0 77 Fourth Avenue, Waltham =
MA 02451 =E2=96=A0 Main Office Toll Free Number: +1 855.577.4323
Contact Customer Support: https://my.rocketsoftware.com/RocketCommunity/RCE=
mailSupport
Unsubscribe from Marketing Messages/Manage Your Subscription Preferences - =
http://www.rocketsoftware.com/manage-your-email-preferences
Privacy Policy - http://www.rocketsoftware.com/company/legal/privacy-policy
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D

This communication and any attachments may contain confidential information=
 of Rocket Software, Inc. All unauthorized use, disclosure or distribution =
is prohibited. If you are not the intended recipient, please notify Rocket =
Software immediately and destroy all copies of this communication. Thank yo=
u.

--=20
You received this message because you are subscribed to the Google Groups "=
openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an e=
mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msg=
id/openssl-users/CH3PPFBCC09965C790141D1358D53A2C770C0582%40CH3PPFBCC09965C=
.namprd07.prod.outlook.com.