Re: NFS4 authentification / fsuid

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Satyam Sharma
Date: Tuesday, September 18, 2007 - 4:27 pm

On Fri, 7 Sep 2007, J. Bruce Fields wrote:

No, not in theory, not in practice. But yeah, restricting an attacker's
ability to hack hardware (by controlling physical access) does take out a
whole class of attack vectors.

But, seriously, such discussion has the tendency to quickly get toooo
theoretical (thus losing practical significance). For example, would we
not also need to prevent the (userspace) superuser from being able to run
arbitrary executables that can modify firmware? Okay, let's say we have
a kernelspace infrastructure of verifying cryptographic signatures on
binaries before executing them ... but how practical/usable is this?
How practically/universally applicable is a system whose security derives
from keeping machines behind locked doors and protected by incorruptible,
armed guard?

Overall, I tend to be unenthusiastic about most schemes that claim to
have solved the user-kernel security problem (with no loss of usability/
practicality).
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
NFS4 authentification / fsuid, Jan Engelhardt, (Thu Aug 30, 7:12 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 7:29 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 7:32 am)
Re: NFS4 authentification / fsuid, Jan Engelhardt, (Thu Aug 30, 7:42 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Aug 30, 8:04 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Aug 30, 8:12 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Aug 30, 2:44 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 6, 1:14 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 6, 1:29 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Sep 6, 8:06 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Thu Sep 6, 8:11 am)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:21 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 4:30 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:32 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 4:35 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 5:56 pm)
Re: NFS4 authentification / fsuid, Trond Myklebust, (Thu Sep 6, 10:14 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Thu Sep 6, 10:47 pm)
Re: NFS4 authentification / fsuid, Bernd Eckenfels, (Thu Sep 6, 11:37 pm)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Fri Sep 7, 8:34 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:12 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:27 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:44 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Tue Sep 18, 4:48 pm)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Tue Sep 18, 10:16 pm)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Wed Sep 19, 5:16 am)
Re: NFS4 authentification / fsuid, Kyle Moffett, (Wed Sep 19, 6:49 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Wed Sep 19, 7:12 am)
Re: NFS4 authentification / fsuid, J. Bruce Fields, (Wed Sep 19, 8:01 am)
Re: NFS4 authentification / fsuid, Valdis.Kletnieks, (Wed Sep 19, 9:38 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 20, 12:03 am)
Re: NFS4 authentification / fsuid, Satyam Sharma, (Thu Sep 20, 12:15 am)