Re: hardlinks to setuid binaries

David Holland <[email protected]> Sun, 27 Mar 2022 23:22:18 +0000
Newsgroups gmane.os.netbsd.devel.security
Message-ID <YkDxqqIwSzXwb/[email protected]>
On Sun, Mar 27, 2022 at 01:47:44PM -0400, Thor Lancelot Simon wrote:
 > Even better, imagine requiring an attribute to be set on a directory
 > in order to _allow_ it to contain setuid executables.  Or device nodes.
 > Wouldn't that, in general, be safer and better than trying to decide all
 > the places where such things should _not_ be allowed?

That is a good idea...

-- 
David A. Holland
[email protected]