Re: httpd(8) log files are world and daemon-readable
Piotr Durlej <[email protected]>
| Newsgroups | gmane.os.openbsd.tech |
|---|---|
| Message-ID | <[email protected]> |
On Thu, Aug 27, 2026 at 11:20:42PM -0400, Brian Brombacher wrote: > Try convincing an inspector from your national DPA that your setup is in compliance and doesn’t violate Article 32 and 25. The design is fundamentally flawed in the eyes of the GDPR. It extends into “willful and negligent” violation of the GDPR. > > You can never have untrusted local users on a production system that is required by law to be secure and private. There is no way you can spin this. Your conclusion is based on an incorrect assumption that the production environment allows uncontrolled access by local, untrusted users. It does not. GDPR compliance under Articles 25 and 32 is not measured by hypothetical worst-case scenarios, but by the presence of appropriate technical and organizational measures proportional to the actual risks. Those measures are in place, documented, and auditable. An inspector evaluates the implemented controls, not speculative interpretations detached from the real architecture. Your claim of a "fundamentally flawed" or "willful and negligent" violation is therefore unfounded. Kind regards, Piotr Durlej