Quote of the week
Posted Jul 10, 2006 18:17 UTC (Mon) by
emk (guest, #1128)
Parent article:
Quote of the week
OK, so users shouldn't extract or compile kernels as root. I'm OK with that as a matter of policy (and it's good advice for compiling any software).
On the other hand, lots of distributions and users still follow the old broken workflow, and are exposing themselves to a root compromise. How hard is it, exactly, to set reasonable default permissions on the files in the tarball? I know plenty of sysadmins who don't read every post by Linus to lkml, and who didn't hear about this policy change.
And why on earth is a vital system component being packaged on a box with world-writable files, anyway?
(
Log in to post comments)