Re: A new kind of security needed
- From: Patrick Proniewski <patpro@xxxxxxxxxx>
- Date: Thu, 17 Jul 2008 08:59:00 +0200
On 17 juil. 08, at 08:24, Jason Stone wrote:
Is anyone else nervous trusting all his programs to have access to all his files? Is there already a reasonable solution to this problem?
It makes me nervous for, say, Firefox and its plugins to be able to read and write every file I own, whether it's gnucash, ~/.ssh, or other sensitive files.
Absolutely. Right now, I use different logins for different things (casual web surfing, financial stuff, snd work), but it's inconvenient and far from fullproof.
Capabilities or MAC systems could be used here -- someone just has to put in the work to make it happen.
What about sandbox/chroot ?
Apple has designed such a system for Mac OS X 10.5, and even if it's not fully functional now, it's probably interesting.
<http://developer.apple.com/documentation/Darwin/Reference/ManPages/man7/sandbox.7.html >
patpro
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: A new kind of security needed
- From: Robert Watson
- Re: A new kind of security needed
- References:
- A new kind of security needed
- From: Matt Reimer
- Re: A new kind of security needed
- From: Jason Stone
- A new kind of security needed
- Prev by Date: Re: A new kind of security needed
- Next by Date: Re: A new kind of security needed
- Previous by thread: Re: A new kind of security needed
- Next by thread: Re: A new kind of security needed
- Index(es):