3 ms·
> be able to install in there as an unprivileged user is utterly ridiculous. this. I'm using homebrew and installing every package as my own user is a security
by devdoomari 10y ago
> be able to install in there as an unprivileged user is utterly ridiculous.
this. I'm using homebrew and installing every package as my own user is a security risk. One security mistake in a package can interfere with my main user account's files / other packages / etc.
Other package managers (apt, yum, macports, etc.) install each package as separate users (e.g. Mysql as user 'mysql') to prevent bad packages from 'leaking'.
- the_mitsuhiko 10y agoHow is it a security risk?
- viraptor 10y agoAnyone taking control of your account can take control of (for example) database you installed, without going via the database's authorization system. Not a huge issue on a laptop, I'd say. But in general - your normal user should be able to modify the binaries you're running without gaining some higher auth level. (for example via sudo)
- rbanffy 10y agoLet's say the code of something you are running locally has a SQL injection vulnerability that allows someone to run arbitrary code on your machine (let's imagine you are running a local copy of your client's WordPress blog with dozens of plugins you don't know where they came from). When the user you, the intruding code runs as you, with your privileges. When the service runs as a restricted user, that's all access the intruder gets. Next time you go to a meetup, try to do an nmap on your surroundings.