Re: Fedora/RedHat is moving is a similar direction
Sergio Tortosa Benedito <[email protected]>
| Newsgroups | gmane.linux.distributions.gobo.general |
|---|---|
| Message-ID | <CAPiRi8OK2rY_Ts_LUdqUa87Qctb79j7gpxSXp+RgEELaV_XCDA@mail.gmail.com> |
-- Best regards, Sergio El 5/9/2015 19:10, "Sergio Tortosa Benedito" <[email protected]> escribió: > > Hmm.. then why is that not good enough for applications too? > > Those are different level, one thing is to isolate users so that their bad impact on a system is minimum, so we want to isolate apps so that their impact on the user (and thus on the system is minimum). > > >I know on > > my Debian system Apache runs as www-data user, for instance. > > Oops, you got me there, but I guess is a way to maintain things clean... I wasn't thinking clearly on the last one, this makes sense for Apache, a really big application which is an entry point for an attack, that way (theorically) an attack will be contained and should affect nothing more than apache, but again try to think about this: so if two users want to use libreoffice, if libreoffice were to be executed its own user, how, for example, would user1 ask to load libreoffice a document in a way that only that user could do that and not any other user (like eviluser, for example)? This was the first one it came to my mind, if you want, I can give several examples and situations. Again, this works for server applications which only access their own file, but for applications actual users would use. _______________________________________________ gobolinux-users mailing list [email protected] http://lists.gobolinux.org/mailman/listinfo/gobolinux-users