Re: [rfc] change default setuid permissions from 4755 to 4711

Tomasz Kłoczko <[email protected]> Sun, 7 Aug 2005 20:34:23 +0200 (CEST)
Newsgroups gmane.linux.pld.shadow.general
Message-ID <[email protected]>
On Fri, 5 Aug 2005, Mike Frysinger wrote:
[..]
> i never said SbO was a real defense (which i pointed out in this thread)
> because it isnt.  my point was to restrict information which is not needed
> for normal running of a system.

Excuse me .. not needed ?
So how can you calculate checksum for example for su and confront this 
with information stored in distribution packages and/or system installed 
packages database .. from non-root account ?
Why in "your word" I must be root for check system integrity ?
Binary code of *all* binaries in your system this not classified 
information and restricting access to this information is like choping 
tree on you sit.

kloczek
-- 
-----------------------------------------------------------
*Ludzie nie majÂą problemĂłw, tylko sobie sami je stwarzajÂą*
-----------------------------------------------------------
Tomasz KÂłoczko, sys adm @zie.pg.gda.pl|*e-mail: [email protected]*