4 ms·
| If a vulnerability requires root or elevated privileges to occur, don’t waste your time resolving it. If the attacker already has root, you have bigger probl
by kryptn 15y ago
| If a vulnerability requires root or elevated privileges to occur, don’t waste your time resolving it. If the attacker already has root, you have bigger problems on your hands.
Well said. I've never considered it that way.
| No system is perfect.
A perfect system is an unplugged system.
- foxhop 15y ago| A perfect system is an unplugged system. I like that quote, do you recall the owner?
- count 15y agoThat's because it's just not true. There are systems in place where even root cannot do things (such as SELinux based systems). These are systems where the security and integrity of the data is paramount - the system is a mere vessel to protect the data. The data may not be allowed to be seen or manipulated by 'root' or other system administrator type user. I'll grant you, these types of systems are rare - but they do exist.
- foxhop 15y agoSELinux might appear more secure, but I seriously doubt the its flawless.
- count 15y agoNothing is flawless. It's significantly flawless enough to not matter at the moment, however.
- mentat 15y agoI believe that SELinux was developed in cooperation with federal agencies quite interested in security. While not flawless it's one of the best systems currently available. Claiming that any system that's not flawless is therefore not interesting is the classic security strawman.