NO_ATIME?
Posted Jul 1, 2004 12:31 UTC (Thu) by
Peter (guest, #1127)
In reply to:
NO_ATIME? by Ross
Parent article:
Kernel release status
(Yes, they can't be trusted now when the user can edit the inode
time info but that isn't the case for system files.)
I can't think of a lot of reasons why hiding that you have accessed a
file really is security-sensitive. Arbitrarily changing the atime or
mtime, yes, that's something you don't want people doing to files they don't
have permissions to - but merely not updating the atime - that seems
rather less serious. It's not like the atime gives you a real audit trail,
after all - it doesn't say who last read a file.
(
Log in to post comments)