Re: Directory permissions (keep root out)

From: Michael Heiming (michael+USENET_at_www.heiming.de)
Date: 01/23/04


Date: Fri, 23 Jan 2004 00:07:52 +0100

NeoSadist <neosad1st@charter.net> wrote:
> D. Hampton Finger wrote:
[..]
> > How can I setup a directory so that root can't gain access to it? This
> > is general UNIX it is true, but the system in question is RedHat linux,
[..]

> There is no possible way that I know of:
> 1) Root in unix/linux has no restrictions

Ack, unless you are running some special kernel restricting
rootly powers.

[..]
> the person cannot read or write your files. Lastly, if you need to you
> could encrypt all those files to a password that only your team knows. The
> non-US citizen as root could copy them or delete them, but it would take
> them longer to crack the encryption scheme, and if they don't then all they
> have is garbage.

Only if you don't decrypt the files logged in, or it would be
trivial for UID 0.

-- 
Michael Heiming
Remove +SIGNS and www. if you expect an answer, sorry for 
inconvenience, but I get tons of SPAM


Relevant Pages

  • Re: Directory permissions (keep root out)
    ... Hampton Finger wrote: ... > How can I setup a directory so that root can't gain access to it? ... under US law and his country's laws. ... them longer to crack the encryption scheme, and if they don't then all they ...
    (comp.os.linux.security)
  • Re: GUI login screen.
    ... > [Please wrap your lines! ... >> made root. ... And you now have two possible passwords to gain access to super-user ... `'` proud Debian admin and user ...
    (Debian-User)
  • Re: ssh: Permission denied
    ... Change the configuration to allow remote root login. ... hacker needs is the correct password in order to gain access, ... the risk must not be from password-bots. ...
    (Fedora)
  • Re: I dont want a keyring password
    ... it is open to any person who has cracked into your account. ... And root can't casually read it. ... have to execute an exploit to gain access. ... This is by definition of the Unix security model -- if root ...
    (Fedora)

Quantcast