The trouble with dropping groups
The trouble with dropping groups
Posted Nov 20, 2014 7:45 UTC (Thu) by neilbrown (subscriber, #359)In reply to: The trouble with dropping groups by luto
Parent article: The trouble with dropping groups
A sysctl which identified a range of groups that could be dropped wouldn't be too tedious.
Then it would only be logical to also identify a range of groups that could freely be added - if the goal is to lose privileges, and adding groups achieves that, then maybe it should be allowed.
Having observed that, it starts to feel very much like the wrong solution to the problem.