--- Cliffe <cliffe@ii.net> wrote:Now that's a refreshing comment. Thank you. There are people (I'm not one of them) who figure that you can solve all the security problems by applying sufficiently fine granularity of on/off permissions. While you're at it, how about a capability for each possible directory entry name? Of course they don't. The only problem they are intended to solve, and I really mean this, is the association of uid 0 with privilege. That's it. You would be better off with a single CAP_GODLIKE than with uid 0 having all privilege all the time. Fine grained capabilities are a bonus, and there are lots of people who think that it would be really nifty if there were a separate capability for each "if" in the kernel. I personally don't see need for more than about 20. That is a matter of taste. DG/UX ended up with 330 and I say that's too many. Casey Schaufler casey@schaufler-ca.com -
| Andi Kleen | [PATCH] [4/58] x86_64: Don't rely on a unique IO-APIC ID |
| Glauber de Oliveira Costa | [PATCH 1/19] unify desc_struct |
| Andrew Morton | Re: [BUG] New Kernel Bugs |
| Linus Torvalds | Linux 2.6.27-rc8 |
git: | |
| Matthieu Moy | Re: strbuf API |
| walt | git versus CVS (versus bk) |
| Jakub Narebski | Re: [RFC] Git User's Survey 2008 |
| Nguyễn Thái Ngọc | [PATCH] git-grep: add --color to highlight matches |
| Marcos Laufer | dmesg IBM x3650 OpenBSD 4.3 |
| Theo de Raadt | That whole "Linux stealing our code" thing |
| Leon Dippenaar | New tcp stack attack |
| bofh | Re: OpenBSD firewalls as virtual machine ? |
| Hugh Dickins | Re: [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| Jiri Bohac | PATCH: fix bridged 802.3ad bonding |
| Linus Torvalds | Re: [GIT]: Networking |
| Jarek Poplawski | Re: [PATCH] net_sched: Add qdisc __NET_XMIT_STOLEN flag |
