[6187] in RedHat Linux List
Re: Suggestion for next redhat release (or a fix).
daemon@ATHENA.MIT.EDU (Wojtek Pilorz)
Tue Nov 26 09:59:39 1996
Date: Tue, 26 Nov 1996 15:37:06 +0100 (MET)
From: Wojtek Pilorz <wpilorz@celebris.bdk.lublin.pl>
To: Chris Evans <chris@ferret.lmh.ox.ac.uk>
Cc: redhat-list@redhat.com
In-Reply-To: <Pine.LNX.3.95.961125183655.17775A-100000@ferret.lmh.ox.ac.uk>
Resent-From: redhat-list@redhat.com
Reply-To: redhat-list@redhat.com
On Mon, 25 Nov 1996, Chris Evans wrote:
> Date: Mon, 25 Nov 1996 18:41:43 +0000 (GMT)
> From: Chris Evans <chris@ferret.lmh.ox.ac.uk>
> To: redhat-list@redhat.com
> Subject: Suggestion for next redhat release.
>
>
> I notice that group "disk" is shared between both hard AND floppy drives.
> I really think that floppy block devices should be group 'floppy', (and
> permission -rw-rw---) so that people logging in at the console can be
> given the extra group 'floppy' via the new powerful PAM modules.
>
Yes !!!
I would heartily recommend that.
I used to work with Slackware 3.0, where floppy devices had group floppy,
and like that a lot.
Now, with RHL 4.0, I have created extra device for floppy
( with the same major/minor as original one), and owned my normal
login id;
This not very elegant, but seems to work for me; however, I am not sure
if there is not some kind of danger hidden in this workaround
(when a device is being accessed through several /dev entries; locks?,
caching ?, something else ??)
> Similar considerations for new groups 'audio' and _MOST DEFINITELY_
> 'xpriv'. This latter one is allowed to execute the XF86_* binaries,
> "others" should not be able to do this. Someone logging in via telnet can
> type 'startx' and really p*** off people at the console.
>
Hmm, sounds dangerous.
Thank you for pointing that out ...
> Read permission for "other" on /dev/fd0 etc. is also somewhat lax in the
> security department. See above solution.
>
> Comments..?
>
> Chris.
>
Regards,
Wojtek Pilorz
--
PLEASE read the Red Hat FAQ, Tips, Errata and the MAILING LIST ARCHIVES!
________________________________________________________________________
http://www.redhat.com/RedHat-FAQ http://www.redhat.com/RedHat-Errata
http://www.redhat.com/RedHat-Tips http://www.redhat.com/mailing-lists
------------------------------------------------------------------------
To unsubscribe: mail -s unsubscribe redhat-list-request@redhat.com < /dev/null