4 ms·
Strengthening controls on a system while simultaneously not breaking any client is an incredibly difficult goal. Unfortunately, unless there is a single, unite
by stestagg 8y ago
Strengthening controls on a system while simultaneously not breaking any client is an incredibly difficult goal.
Unfortunately, unless there is a single, united team focussed on this single goal (kernel is not by design). Then some fingers will be burned, because of the complexity of getting it right.
Some contributors will struggle, and others will fail at it. Unfortunately, that’s just stats.
- hedora 8y agoThe systemd and various “secure” linux teams keep adding poorly thought out access controls that no one understands, that have escoteric loopholes and break things in terrible ways. I wish they’d just move back to the original unix permission scheme, plus jails. BSD and solaris did much better jobs of this a decade ago. Hopefully one of those will eventually take over again.
- JdeBP 8y agoSolaris and (some of) the BSDs have NFS-style ACLs, and do not have the original Unix permission scheme either.