3 ms·
Poettering is very convinced that this is not a bug. https://news.ycombinator.com/item?id=11008771 https://news.ycombinator.com/item?id=11008771 https://githu
by notabee 3y ago
Poettering is very convinced that this is not a bug.
https://news.ycombinator.com/item?id=11008771 https://news.ycombinator.com/item?id=11008771
https://github.com/systemd/systemd/issues/2402 https://github.com/systemd/systemd/issues/2402
- nine_k 3y agoI've read the second thread today. I'm running a "Poettering-free" distro (Void Linux), but it does not have this mitigation either.
- anaisbetts 3y agoI mean, I agree with him - read-only mounts are not a security boundary, user accounts and permissions are the security boundary.
- nine_k 3y agoGuard rails are not a security boundary, but are helpful nevertheless. You can still do that, but it becomes harder to do by mistake.
- extraduder_ire 3y agoI am still amazed this isn't an option in the boot menu that's off by default.