Fedora to (try to) remove setuid files for F15
Fedora to (try to) remove setuid files for F15
Posted Oct 29, 2010 14:06 UTC (Fri) by SEJeff (guest, #51588)In reply to: Fedora to (try to) remove setuid files for F15 by nelhage
Parent article: Fedora to (try to) remove setuid files for F15
There are still administrators who couldn't figure out how to remove a file you set immutable with chattr +i to save their life. There are still lots of nix professionals who don't get {set,get}facl when it is actually very easy to learn. At least gnu ls shows these files in red when color mode is enabled or a + on the right hand side of the permissions line for facls. Plenty of people don't understand how to use or tweak their shiney Linux userland to the the max. As a Linux professional I would consider myself one that hasn't "learned it all".
That will never stop. However, this is a noteworthy goal. Preventing su / sudo is not the point. Preventing bugs in applications that think they need root and then perhaps drop privs _is th point_. To that end, it is a noble goal and one I look forward to seeing the results of.
Just like how SELinux prevents a lot of stock exploits and worms cold, this is another layer in the security bag-o-tricks.
