4 ms·
A normal user application, i.e. firefox, should not have access /var/log/messages. The zeitgeist db can be queried by any application running with the users pri
by baghira 11y ago
A normal user application, i.e. firefox, should not have access /var/log/messages. The zeitgeist db can be queried by any application running with the users privilege.
Although to be fair the fedora 22 installation I'm running allows me read the logs launching journalctl as a user, so there's that.
I don't think zeitgeist has much to do with the Windows behaviour (or with the scopes behaviour). It's just a potential security risk, albeit a minor one.
- icebraining 11y agoA normal user application, i.e. firefox, should not have access /var/log/messages. The zeitgeist db can be queried by any application running with the users privilege. Zeitgeist itself runs with the users privilege (it's not a system daemon, it's started by the user's session), so that hypothetical application could simply log the data itself. There's no leak of information to underprivileged processes.
- baghira 11y agoI know that, what I meant was that there is information stored about the past, that a malicious application could not get otherwise (i.e. it can record stuff only from the moment it is installed). On similar note, I rememember someone arguing that the baloo/nepomuk db was a security threat, I guess since it makes slightly easier to search among the files on the system for a string like "password". Both claims are technically true, and in neither case I believe they are practically relevant, neither for security nor for privacy. I was nitpicking, I guess.