Re: setuid/setgid technology - OLD and NASTY

Anthony Barbachan (barbacha@trill.cis.fordham.edu)
Sat, 18 Jul 1998 02:40:29 -0400


-----Original Message-----
From: Linux Kernel list <linkern@lcjdap.soroscj.ro>
To: Linus Torvalds <torvalds@transmeta.com>; Alan Cox
<alan@lxorguk.ukuu.org.uk>; linux-kernel@vger.rutgers.edu
<linux-kernel@vger.rutgers.edu>
Date: Friday, July 17, 1998 1:16 PM
Subject: setuid/setgid technology - OLD and NASTY

>
>
> Setuid/setgid technology is an old technology belonging to the 70's.
>It was pretty confortable at that time but now it's not really actual and
>it's more like a pain in the system. It would be possible to replace this
>with 'something' - you decide what - in kernel land with something really
>secure. It's near year 2000 now. I would love to see Linux get rid of this
>kind of ballast.
>
> It would make a safer world ;)
>
>Tell me where if I'm wrong. And if it is an issue that you are working or
>planning to work on please forgive me.
>
> Thank YOU!
>

At least keep it as an option for backward compatibility. Perhaps also an
option to only allow suids to a non-root user. A logging facility of suids
might also be useful.

>
>-
>To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
>the body of a message to majordomo@vger.rutgers.edu
>Please read the FAQ at http://www.altern.org/andrebalsa/doc/lkml-faq.html
>

-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.altern.org/andrebalsa/doc/lkml-faq.html