Fedora to (try to) remove setuid files for F15
Fedora to (try to) remove setuid files for F15
Posted Nov 17, 2010 4:39 UTC (Wed) by Baylink (guest, #755)Parent article: Fedora to (try to) remove setuid files for F15
My snap reaction to this, and I'm certainly willing to be proven wrong, is that this pushes the decision about how to make a given program secure from the programmer, who a) knows the code intimately, and b) only has to do it once, out to either the various distribution managers (ca 100's), or the end system administrators (ca 1,000,000's), with decreasing levels of understanding of both the code, and the security process, and thereby logarithmically increasing levels of questionably protected attack surface...
IE: that's it's a thoroughly miserable idea from up here at 40,000ft, no matter how clever it looks at 5000ft.
Why am I wrong? :-)
