Re: Fedora/RedHat is moving is a similar direction

Sergio Tortosa Benedito <[email protected]>
Newsgroups gmane.linux.distributions.gobo.general
Message-ID <CAPiRi8OK2rY_Ts_LUdqUa87Qctb79j7gpxSXp+RgEELaV_XCDA@mail.gmail.com>
-- Best regards, Sergio
El 5/9/2015 19:10, "Sergio Tortosa Benedito" <[email protected]> escribió:

> > Hmm.. then why is that not good enough for applications too?
>
> Those are different level, one thing is to isolate users so that their
bad impact on a system is minimum, so we want to isolate apps so that their
impact on the user (and thus on the system is minimum).
>
> >I know on
> > my Debian system Apache runs as www-data user, for instance.
>
> Oops, you got me there, but I guess is a way to maintain things clean...

I wasn't thinking clearly on the last one, this makes sense for Apache, a
really big application which is an entry point for an attack, that way
(theorically) an attack will be contained and should affect nothing more
than apache, but again try to think about this: so if two users want to use
libreoffice, if libreoffice were to be executed its own user, how, for
example, would user1 ask to load libreoffice a document in a way that only
that user could do that and not any other user (like eviluser, for
example)? This was the first one it came to my mind, if you want, I can
give several examples and situations.

Again, this works for server applications which only access their own file,
but for applications actual users would use.

_______________________________________________
gobolinux-users mailing list
[email protected]
http://lists.gobolinux.org/mailman/listinfo/gobolinux-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.