• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: setuid for priv sockets?
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: setuid for priv sockets?


  • Subject: Re: setuid for priv sockets?
  • From: Stephen Hoffman <email@hidden>
  • Date: Mon, 27 Oct 2008 17:49:35 -0400
  • Organization: HoffmanLabs LLC

Damien Sorresso writes:

We're strongly (and I do mean strongly) trying to move people off of setuid binaries. If it's a command line application, you can just require that the user run it as root or with sudo if performing actions that require access to this privileged port.

Not passing out root or sudo access is a common practice in various production and security-conscious environments. Within those environments (and I deal with folks that are severely allergic to passing out root access), setuid can be an invaluable palliative.


I'm quite willing to move to another approach or environment or tool or interface here. But suggesting that they pass out root access as a solution for starting up certain command-line tools is just going to get me a heaping raft of static with these good folks.

Please don't take away setuid without an alternative. And no, sudo isn't a solution.

_______________________________________________
Do not post admin requests to the list. They will be ignored.
Darwin-dev mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:
This email sent to email@hidden


  • Follow-Ups:
    • Re: setuid for priv sockets?
      • From: "Jordan K. Hubbard" <email@hidden>
    • Re: setuid for priv sockets?
      • From: Damien Sorresso <email@hidden>
    • Re: setuid for priv sockets?
      • From: "Duane Murphy" <email@hidden>
    • Re: setuid for priv sockets?
      • From: "Finlay Dobbie" <email@hidden>
  • Prev by Date: SOL_NDRVPROTO
  • Next by Date: Re: setuid for priv sockets?
  • Previous by thread: Re: setuid for priv sockets?
  • Next by thread: Re: setuid for priv sockets?
  • Index(es):
    • Date
    • Thread