Local root vulnerability in snap-confine
Local root vulnerability in snap-confine
Posted Feb 18, 2022 21:11 UTC (Fri) by ms-tg (subscriber, #89231)In reply to: Local root vulnerability in snap-confine by mpr22
Parent article: Local root vulnerability in snap-confine
I wonder if there are steps that, over some years, could help make the unknown number of people visible? For example, what if Linux, either in the file systems or more likely in distro-level utilities, simply detected filenames that violated certain rules, and let the user know that these existed and might need to be renamed to follow a proposed RFC naming convention in the future if it becomes accepted?
Perhaps users could opt-in to also reporting counts back to a central server?
I'm even picturing a nice web page, the way big security vulnerabilities have these days? Maybe 'linux-filenames-rfc.io'? Which could include the latest text of the proposal, links to Github where changes can be proposed, mailing lists where it is discussed, etc?
Using these sorts of community consensus approaches, might it be possible to get more of a defined sense of how often how big a real-world impact would be felt by any proposed reduction in Linux filename permissiveness?
