4 ms·
Not a LITTLE sarcastically, no. No one has yet provided evidence that privileged ports create even a single security issue. While there's lots of huffing and
by antimeme 4y ago
Not a LITTLE sarcastically, no.
No one has yet provided evidence that privileged ports create even a single security issue. While there's lots of huffing and puffing in the original article (including someone confusing privileged ports with IP based authentication, which is effectively dead), the closest it gets is to say that dropping privileges in a server is a pain. And then they go on to show off a one line configuration change that would disable privileged ports system wide. So do that if it makes sense for you.
What doesn't make sense would be to abandon decades of practice that real people (more than three in Finland, actually) rely upon because some people are too lazy to make a trivial change to their systems. And let's get real: 99.9% of people are never going to want to run a web server on their computers. You're just arguing that your portion of that 0.1% -- let's be a LITTLE sarcastic and call them five penguins in Antarctica! -- are more important than the rest.
- foldr 4y agoIf the best you can say for the current defaults is that they're easy to change, then it's probably time to change the defaults. The article doesn't just say that dropping privileges is a 'pain', but points out that a security model based on binding a port as root (or another specially privileged user) and then dropping privileges has been a persistent source of security issues. The article links to several detailed explanations of this (e.g. https://wibblement.blogspot.com/2021/11/the-persistent-idiocy-of-privileged.html https://wibblement.blogspot.com/2021/11/the-persistent-idioc..., https://www.staldal.nu/tech/2007/10/31/why-can-only-root-listen-to-ports-below-1024/ https://www.staldal.nu/tech/2007/10/31/why-can-only-root-lis...). The one-line configuration change also doesn't work well if the service is executed via an interpreter or VM. Authbind also has its edge cases: https://www.reddit.com/r/golang/comments/cqlpnq/comment/ewyluyh/ https://www.reddit.com/r/golang/comments/cqlpnq/comment/ewyl...