LWN.net Logo

NO_ATIME?

NO_ATIME?

Posted Jul 1, 2004 12:31 UTC (Thu) by Peter (guest, #1127)
In reply to: NO_ATIME? by Ross
Parent article: Kernel release status

(Yes, they can't be trusted now when the user can edit the inode time info but that isn't the case for system files.)

I can't think of a lot of reasons why hiding that you have accessed a file really is security-sensitive. Arbitrarily changing the atime or mtime, yes, that's something you don't want people doing to files they don't have permissions to - but merely not updating the atime - that seems rather less serious. It's not like the atime gives you a real audit trail, after all - it doesn't say who last read a file.


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds