LWN.net Logo

Security Risks and Human Nature

Security Risks and Human Nature

Posted Apr 10, 2006 19:04 UTC (Mon) by jmorris42 (subscriber, #2203)
In reply to: Security Risks and Human Nature by smoogen
Parent article: .desktop files and security

> In the end, there are always trade-offs between security and usability...

Granted. But this one is simple to decide as soon as it is described. We have a file that can appear as anything it wishes to inside the graphical environment as both the icon and caption text being totally decided by the .desktop file itself, while the user has little or no way to discover what it will do when activated other than actually activating it or dropping to a command line and invoking less on it. But it can do absolutely anything it wants with the full execution rights of the user without requiring any privleges other than to be readable. So just what is the point of retaining the execute bit in file systems if this stands?


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds