Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Cleanliness next to Rootliness
Daniel Hanson, 2005-04-27

Linspire's arguments to only run a desktop system as root has everything to do with privilege seperation, privilege escalation, and some design choices made along the way.

Comments Mode:
Amen! 2005-04-27
Anonymous
"Run everything as root, there's no big security issues here" is the biggest load of spit I've heard in a while. Ubuntu operates on a rootless security model, SELinux/grsecurity/RSBAC aim to establish roles so that root processes have limited scope, and Zones are like a chroot()^10. These things exist because quality preventative security measures are needed by default when 15 year-olds can download some code that will turn Grandma's machine into a digital weapon wielded against the rest of us. Oh, and good ol' Granny can change her wallpaper without being root in other distros, that functionality has been in KDE and GNOME for years. What happened to you Mr. MP3.com? Money changes people...

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/321/31667#31667
Cleanliness next to Rootliness 2005-04-28
Anonymous
Cleanliness next to Rootliness 2005-04-28
Todd Knarr (2 replies)
Cleanliness next to Rootliness 2005-04-28
dph - author
Cleanliness next to Rootliness 2005-05-05
Anonymous
"Most important" - oh no... 2005-05-04
Phlebas







 

Privacy Statement
Copyright 2008, SecurityFocus