3 ms·
> The fix is easy: ship Linux distributions so that privileged ports start from 80 to begin with. net.ipv4.ip_unprivileged_port_start=80 But then this cou
by bArray 4y ago
> The fix is easy: ship Linux distributions so that privileged ports start from 80 to begin with.
net.ipv4.ip_unprivileged_port_start=80
But then this could potentially break other security models the author is not aware of that are built on this assumption. I think the middle ground here would be to have a setting to de-root a specific port.
Or whitelist a specific process for binding. Or create a server user (www is often used) that's purpose is only to have root for the sake of binding, and nothing else. Better yet, it would only be able to access resources within a tightly restricted range (file directories, ports, RAM, CPU, etc).
I don't see how unrestricted 80-1024 is actually the best answer here, given the legacy cruft that will take time to deal with.