Re: httpd(8) log files are world and daemon-readable

Brian Brombacher <[email protected]>
Newsgroups gmane.os.openbsd.tech
Message-ID <[email protected]>
Try convincing an inspector from your national DPA that your setup is in compliance and doesn’t violate Article 32 and 25.  The design is fundamentally flawed in the eyes of the GDPR.  It extends into “willful and negligent” violation of the GDPR.

You can never have untrusted local users on a production system that is required by law to be secure and private.  There is no way you can spin this.

> On Aug 27, 2026, at 10:50 PM, David Leadbeater <[email protected]> wrote:
> 
> On Thu, Aug 27, 2026 at 08:33:29PM -0400, Brian Brombacher wrote:
>> What stops your malicious local users from running netstat -an in a
>> tight loop and recording every connection timestamp and IP address?
>> There goes your “GDPR Compliance” out the window.
> 
> On one shared system I force untrusted users into a different rdomain(4)
> via SSH config, the intent isn't to hide netstat output but it is a side
> effect. Obviously things like cron escape the SSH rdomain configuration,
> so you then have to consider those cases and handle them somehow too.
> 
>> Your threat model is fundamentally flawed.  Don’t mix candied apples
>> with anchovies and expect something edible.
> 
> Don't expect it to work out of the box but I wouldn't say fundamentally
> flawed. Many things are configurable.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.