28 ms·
I think that from the security perspective, the more important change in Plan 9 was dropping the notion of a privileged "root" account. This forces you to redes
by drybjed 5y ago
I think that from the security perspective, the more important change in Plan 9 was dropping the notion of a privileged "root" account. This forces you to redesign your system from the ground up. No more "root" to mount devices in the filesystem means that unprivileged users need to be able to mount things. But allowing users to mount things in the global namespace can mess things up, so instead we need to implement private per-process namespaces that users can mount and bind stuff in. Bam - containerized applications are the norm, there's no Docker, there's no Flatpak, there exists something like Kubernetes that can handle orchestration but doesn't concern itself with containerization and sandboxing.
When you plug in an USB device it shows up in the list of devices. Then you can mount it as your unprivileged user in the private namespace of your own shell, no issues there with permissions. If that USB device has a filesystem that supports user/group permissions, then you have access only to the files that you own.
- kaba0 5y agoI don't think it's that easy. I'm really am not familiar with Plan 9, but I assume /dev 's analog folder is a privileged directory, where the new USB device will appear dynamically. On what basis will my user have permission to do anything with it? You need some logic there for eg. a block device available through these USB ports can have a less privileged owner. But just because it is a file/namespace, it is not a solved problem at all.
- drybjed 5y agoAccording to the Plan 9 Desktop Guide[1], when you plug your USB stick and the OS supports the filesystem, it will be mounted in the /shr directory. From there you can bind-mount stuff you need to wherever. Alternatively, you can mount the disk using the fileserver (dossrv for DOS, etc.) wherever you need. Your user will have access to devices when it's included in the required system groups, 'sys' IIRC. It might get added to that group when it is created by the "hostowner" user, usually "glenda". If you don't know Plan 9, you should check out the linked user guide, it's an excellent introduction to the concepts. [1]: https://pspodcasting.net/dan/blog/2019/plan9_desktop.html https://pspodcasting.net/dan/blog/2019/plan9_desktop.html
- squiggleblaz 5y agoIn general, how do control mounting - the fact that I plugged a USB device into a shared computer doesn't mean anyone should be able to mount it. Root allows me to trust one person, rootless seems to require me to trust everyone? Also, the major threats to my security from my laptop are not other users. I'm not scared of the other users of my laptop. Who even are they? they're people who've already taken advantage of security holes in applications to break in. The people who I am concerned with are the authors of the applications that run. It's more like reading the file I want to publish vs data exfiltration: I want the application to engage in this class of actions - but only the members of this class that I authorise, not everything. I want Firefox to be able to read and write within my home directory, but under no circumstances should a bug in Firefox allow a website to read a file I haven't given it. But I also don't want my private file to be somehow in the private namespace of a certain program. Private files are not the property of a foreign program, they're my property. I want to know where they are so I can back them up, replace them atomically for all programs that use it etc. The Android approach of making my private information the property of some semi-trusted application author is crazy. To me, it seems like a secure system would not give a program access to global namespaces like the filesystem nor to be able to enumerate local resources. The program could have its own state and configuration stores, but when it wants to access a file, it asks for permission to read a file, the system asks me how to fulfil that (i.e. pops up a file selection interface), I make a choice, the system passes a file descriptor, the program knows that it uses 7 to read and write. But the system doesn't know that it's getting /home/me/downloads/ketchup-and-mayo.jpg. Likewise, the system asks for my location, and I get a few buttons "give current location, give stored location, spoof". Does plan9 address this? Android I know is too course-grained. It has enough of this to be annoying but in reality you can either give the program full power over this or that feature or you can give it no power and it probably just won't meaningfully run. I'd love to run every program in a sandbox, but I want to be able to own my files.
- drybjed 5y ago> In general, how do control mounting - the fact that I plugged a USB device into a shared computer doesn't mean anyone should be able to mount it. Root allows me to trust one person, rootless seems to require me to trust everyone? The Linux "root" account, or UID 0, is the same everywhere, and this becomes a problem when you start working in a clustered environments with multiple computers sharing resources. Look at NFS and its multiple versions and that huge fight to protect access via 'root' account. In Plan 9 there's a concept of a "hostowner" account, by convention named "glenda". It's the account that the system is started with, and it only concerns itself with resources on that host, there's no sharing with other systems. The 'glenda' account owns resources of the host and can give access to them to other accounts, either via filesystem permissions or via the "factotum" authentication service. Combine this with the fact that on Plan 9 you can change process privileges and capabilities dynamically, unlike in Linux where this can happen only when process is created, and this creates a really nice and secure environment to work in. > Also, the major threats to my security from my laptop are not other users. I'm not scared of the other users of my laptop. Who even are they? they're people who've already taken advantage of security holes in applications to break in. The people who I am concerned with are the authors of the applications that run. It's more like reading the file I want to publish vs data exfiltration: I want the application to engage in this class of actions - but only the members of this class that I authorise, not everything. > I want Firefox to be able to read and write within my home directory, but under no circumstances should a bug in Firefox allow a website to read a file I haven't given it. Before you start Firefox, you can clean up its private namespace and unmount the sutff you don't want to give it access to. Or create a new private namespace and only mount specific directories from your home directory in it, like /home/user/Downloads. This is basically whitelisting access to the filesystem instead of having to blacklist everything but specific directories which will never be foolproof. > But I also don't want my private file to be somehow in the private namespace of a certain program. Private files are not the property of a foreign program, they're my property. I want to know where they are so I can back them up, replace them atomically for all programs that use it etc. The Android approach of making my private information the property of some semi-trusted application author is crazy. Then create the process namespace from scratch, mount only the files that program is supposed to access and then start that program in there. It will not be able to mount anything else because your home directory or other shared resources will not be reachable by the process. > To me, it seems like a secure system would not give a program access to global namespaces like the filesystem nor to be able to enumerate local resources. The program could have its own state and configuration stores, but when it wants to access a file, it asks for permission to read a file, the system asks me how to fulfil that (i.e. pops up a file selection interface), I make a choice, the system passes a file descriptor, the program knows that it uses 7 to read and write. But the system doesn't know that it's getting /home/me/downloads/ketchup-and-mayo.jpg. Likewise, the system asks for my location, and I get a few buttons "give current location, give stored location, spoof". You can just unmount /dev to disallow access to devices. You can unmount /net to disallow access to the network. > Does plan9 address this? Android I know is too course-grained. It has enough of this to be annoying but in reality you can either give the program full power over this or that feature or you can give it no power and it probably just won't meaningfully run. I'd love to run every program in a sandbox, but I want to be able to own my files. Yes, the notion that privileged access does not exist at all might seem crazy at first, but when you think about it, and imagine how currently "privileged" actions like mounting filesystems could be done without it, it starts to make sense.