Antw: [EXT] Re: Creating executable device nodes in /dev?
"Ulrich Windl" <[email protected]> Wed, 09 Dec 2020 08:58:52 +0100
| Newsgroups | gmane.comp.sysutils.systemd.devel,gmane.linux.hotplug.devel |
|---|---|
| Message-ID | <[email protected]> |
>>> Jarkko Sakkinen <[email protected]> schrieb am 09.12.2020 um 01:15 in Nachricht <[email protected]>: ... > > What's the data that supports having noexec /dev anyway? With root > access I can then just use something else like /dev/shm mount. > > Has there been out in the wild real world cases that noexec mount > of would have prevented? > > For me this sounds a lot just something that "feels more secure" > without any measurable benefit. Can you prove me wrong? I think the better question is: Why not allow it? I.e.: Why do you want to forbid it? Event though I wouldn't like it myself, I could even think of noexec /tmp. Regards, Ulrich