Re: Netowrk connectivity (was: segfault on font ...)

Andrew Suffield <[email protected]>
Newsgroups gmane.comp.graphics.y.devel
Message-ID <[email protected]>
On Wed, May 19, 2004 at 10:34:03AM +0800, Rogelio M.Serrano Jr. wrote:
> >However, this need not be implemented in Y, should not be, and
> >probably *will* not be; it's completely the wrong way to go about it,
> >from the perspectives of security, performance, and
> >usability. Xsecurity mechanisms other than MIT-MAGIC-COOKIE-1 are
> >almost never used, and even that is overkill for the scenarios in
> >which it is used. UID-based authentication over unix domain sockets
> >should be all we ever need in the server.
> >
> 
> Is that why X never put security in the protocol? Is SSH the oinly 
> secure network transport available?

X did put security in the protocol. This is why pretty much nobody
*uses* it.

> How should a security policy 
> implemented with uid authentication then?

List of acceptable uids, some of which can modify the list. That's all
you need to build whatever you want in an external layer.

> Is there a super user?

No.

-- 
  .''`.  ** Debian GNU/Linux ** | Andrew Suffield
 : :' :  http://www.debian.org/ |
 `. `'                          |
   `-             -><-          |
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAq2etlpK98RSteX8RAlq2AJ9RelKzsi10iRB7IlUakFezvk3flwCeMuH4
J5VDACloPt6NwTEMUk/NMSY=
=ISUF
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.