3 ms·
This would enable a lot of attacks.
by vbernat 10mo ago
This would enable a lot of attacks.
- goku12 10mo agoCould you elaborate?
- deleted 10mo ago[deleted]
- oasisaimlessly 10mo agoNow anybody with root/sudo/physical access to the remote machine has full R/W access to your entire home directory.
- goku12 10mo agoWell, what if it's a separate directory meant exclusively for remote systems alone? And what if the remote mount is read-only, perhaps with a writable layer on top using overlayfs that can be discarded on logout?
- vbernat 10mo agoThis now looks very complex.
- goku12 10mo agoIt's actually far less complex than what container runtimes do. I've even done parts of those, which is why I'm able to suggest it. I'm thinking about implementing it and was checking if anybody else wanted to do it or if they foresee any problems that I can't.
- deleted 10mo ago[deleted]