3 ms·
If they don't want you to fling binaries into your home directory they should just mount it noexec. At any rate it doesn't seem like a fantastic security/abili
by jclulow 5y ago
If they don't want you to fling binaries into your home directory they should just mount it noexec. At any rate it doesn't seem like a fantastic security/ability-to-work trade-off. Limit the privileges of the account or you're one exploit away from trouble.
- hamburglar 5y agoMany redundant layers are used to prevent and/or detect security violations, but “don’t install random binaries on prod machines” is a basic tenet. If you need certain tools to do your job, deploy them via proper controlled and audited mechanisms, not via scp.