RE: [EXTERNAL] Re: Using certificates and keys from a list
"'Michael Wojcik' via openssl-users" <[email protected]> Thu, 9 Apr 2026 13:23:51 +0000
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <CH3PPFBCC09965C790141D1358D53A2C770C0582@CH3PPFBCC09965C.namprd07.prod.outlook.com> |
> From: 'Martin Bonner' via openssl-users <[email protected]> > Sent: Thursday, 9 April, 2026 00:38 > If an attacker can=E2=80=99t get code execution inside your app, then why= bother dropping > to the unprivileged user at all? That threat model is too simplistic. There are potential vulnerabilities wh= ich could result in an attacker having limited control over the application= 's behavior, insufficient to revert the effective UID but capable of taking= other actions. Your example of file I/O is an obvious one, but there are p= lenty of others. Changing the EUID is defense in depth. That said, it's probably not the architecture I'd use; I prefer stronger se= paration between privileged and non-privileged functions. But I don't know = enough about the application and its use cases to define one more to my lik= ing. -- Michael Wojcik =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D Rocket Software, Inc. and subsidiaries =E2=96=A0 77 Fourth Avenue, Waltham = MA 02451 =E2=96=A0 Main Office Toll Free Number: +1 855.577.4323 Contact Customer Support: https://my.rocketsoftware.com/RocketCommunity/RCE= mailSupport Unsubscribe from Marketing Messages/Manage Your Subscription Preferences - = http://www.rocketsoftware.com/manage-your-email-preferences Privacy Policy - http://www.rocketsoftware.com/company/legal/privacy-policy =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D This communication and any attachments may contain confidential information= of Rocket Software, Inc. All unauthorized use, disclosure or distribution = is prohibited. If you are not the intended recipient, please notify Rocket = Software immediately and destroy all copies of this communication. Thank yo= u. --=20 You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/CH3PPFBCC09965C790141D1358D53A2C770C0582%40CH3PPFBCC09965C= .namprd07.prod.outlook.com.