|
|
Subscribe / Log in / New account

Re: [PATCH] kernel: make /proc/kallsyms mode 400 to reduce ease of attacking

From:  Ingo Molnar <mingo-AT-elte.hu>
To:  Pavel Machek <pavel-AT-ucw.cz>
Subject:  Re: [PATCH] kernel: make /proc/kallsyms mode 400 to reduce ease of attacking
Date:  Fri, 26 Nov 2010 08:38:34 +0100
Message-ID:  <20101126073834.GC19589@elte.hu>
Cc:  Kyle Moffett <kyle-AT-moffetthome.net>, Marcus Meissner <meissner-AT-suse.de>, torvalds-AT-linux-foundation.org, linux-kernel-AT-vger.kernel.org, tj-AT-kernel.org, akpm-AT-osdl.org, hpa-AT-zytor.com, w-AT-1wt.eu, alan-AT-lxorguk.ukuu.org.uk
Archive‑link:  Article


* Pavel Machek <pavel@ucw.cz> wrote:

> Hi!
> 
> > >   (2) Most of the arguments about introducing "uncertainty" into the
> > > hacking process are specious as well. [...]
> > 
> > It is only specious if you ignore the arguments i made in the previous
> > discussion. One argument i made was:
> 
> Well, but it has downsides, too.
> 
> If I know school server is vulnerable, I can get admin to fix it... if
> I can see dmesg without being root, I can help with problems. I have
> done both before...

Yeah, restricting information is always a double edged sword - and by locking down 
we are implicitly assuming that the number of people trying to do harm is larger 
than the number of people trying to help. It is probably true though - and the 
damage they can inflict is becoming more and more serious (financially, legally and 
socially - and, in some cases, physically) with every year of humanity moving their 
lives to the 'net.

So yes, the time has probably come to lock up "potentially harmful" information from 
the default unprivileged user on Linux - at least from a default kernel policies 
POV.

Thanks,

	Ingo



to post comments


Copyright © 2010, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds