--- Cliffe <cliffe@ii.net> wrote:Now that's a refreshing comment. Thank you. There are people (I'm not one of them) who figure that you can solve all the security problems by applying sufficiently fine granularity of on/off permissions. While you're at it, how about a capability for each possible directory entry name? Of course they don't. The only problem they are intended to solve, and I really mean this, is the association of uid 0 with privilege. That's it. You would be better off with a single CAP_GODLIKE than with uid 0 having all privilege all the time. Fine grained capabilities are a bonus, and there are lots of people who think that it would be really nifty if there were a separate capability for each "if" in the kernel. I personally don't see need for more than about 20. That is a matter of taste. DG/UX ended up with 330 and I say that's too many. Casey Schaufler casey@schaufler-ca.com -
| Tarkan Erimer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg Kroah-Hartman | [PATCH 006/196] Chinese: add translation of oops-tracing.txt |
| Jan Engelhardt | intel iommu (Re: -mm merge plans for 2.6.23) |
| David Miller | Re: [PATCH] Stop pmac_zilog from abusing 8250's device numbers. |
git: | |
| David Miller | [GIT]: Networking |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| Linus Torvalds | Re: iptables very slow after commit 784544739a25c30637397ace5489eeb6e15d7d49 |
