home *** CD-ROM | disk | FTP | other *** search
- Submitted-by: toon@moene.indiv.nluug.nl (Toon Moene)
-
- In article <15ibqsINNc3a@ftp.UU.NET> I wrote:
- > Recently, I had a short discussion with the support staff of ECMWF's
- > Cray Y-MP/8 about the use of chown and chmod u+s on the (new) UNICOS
- > 7.0. An excerpt follows:
- Signs of declining control of English here ^^^^^^^^^^^^^^^^^^^
-
- [ ... Discussion about security aspects of chown and setuid deleted ...]
-
- Thanks to all those kind enough to mail me why chown isn't a good idea in
- ordinary user's hands (I have been too long out of the business of system
- administrating OS's, clearly - got to get mean again :-)
-
- The manual page on my NeXT says it quite succinctly:
-
- Only the super-user can change owner, in order to simplify
- accounting procedures.
-
- where 'accounting' has to be understood in broad terms ...
- Now given that non-root users can't chown, why is letting them chmod u+s
- their own executables a bad idea (Except to protect them against
- themselves :-))
-
- --
- Toon Moene (toon@moene.indiv.nluug.nl)
- Kantershof 269, 1104 GN Amsterdam, The Netherlands
- Tel.: + 31 20 6982029; Fax: + 31 20 6003411
- No Disclaimers; a NeXT at home protects against this occupational hazard.
-
-
- Volume-Number: Volume 28, Number 76
-
-