Security Risks and Human Nature
Posted Apr 10, 2006 19:04 UTC (Mon) by jmorris42
In reply to: Security Risks and Human Nature
Parent article: .desktop files and security
> In the end, there are always trade-offs between security and usability...
Granted. But this one is simple to decide as soon as it is described. We have a file that can appear as anything it wishes to inside the graphical environment as both the icon and caption text being totally decided by the .desktop file itself, while the user has little or no way to discover what it will do when activated other than actually activating it or dropping to a command line and invoking less on it. But it can do absolutely anything it wants with the full execution rights of the user without requiring any privleges other than to be readable. So just what is the point of retaining the execute bit in file systems if this stands?
to post comments)