4 ms·
Beware that there is no consensus that this is a good thing. From Daniel Bernstein(qmail creator) at http://cr.yp.to/qmail/qmailsec-20071101.pdf http://cr.yp.t
by igorhvr 15y ago
Beware that there is no consensus that this is a good thing.
From Daniel Bernstein(qmail creator) at http://cr.yp.to/qmail/qmailsec-20071101.pdf http://cr.yp.to/qmail/qmailsec-20071101.pdf
"I have become convinced that this “principle of least privilege” is fundamentally wrong. Minimizing privilege might reduce the damage done by some security holes but almost never fixes the holes. Minimizing privilege is not the same as minimizing the amount of trusted code, does not have the same benefits as minimizing the amount of trusted code, and does not move us any closer to a secure computer system."
- russelldavis 15y agoThere's no consensus that "reducing the damage done by some security holes" is a good thing? Bernstein mentions it as a distraction (which may be true), but it's better than doing nothing.
- xtacy 15y agoI feel that fixing the security holes has little to do with reducing the damage done due to increased attack surface. If you're a software developer who is not doing security research, and who is mainly interested in some functionality offered by a module, you'd be better off giving the module exactly the privileges it needs, not more and not less. If not, wouldn't OS's run all user-space programs in ring-0? (Maybe I am stretching it a bit) If Bernstein meant that this principle has been misquoted/abused/understood in all wrong ways (like most of the "premature optimization" quotes), then perhaps it makes some sense. :)