3 ms·
This is murky because the most basic UNIX isolation mechanism (UID/GID) is applied across all parts of the system: processes, files, etc. (in a nutshell). Thus
by drvdevd 10y ago
This is murky because the most basic UNIX isolation mechanism (UID/GID) is applied across all parts of the system: processes, files, etc. (in a nutshell).
Thus, when you run some program locally, sometimes it runs as your user/group and sometimes a new user/group is created for it.
From this simple abstraction springs the issue that any (potentially misbehaving) application running locally needs to be treated as if it were a user on its own: with all the quirks a random "user" could bring like deleting files, accessing private information, and so on.
Hence the need for these finer grained access control mechanisms. Any program that you download from the Internet (every program most of us run) might as well be a remote user on your system, in a sense.