Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month, online, via Jitsi Meet.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] Passwords in Source Code?? Or, How to secure interprocess communications?



On 1/31/2015 6:25 PM, Kent Borg wrote:
> Daemons, written in Python, on a machine I fully control.

If you fully control it then you don't need authentication.


> Because this is only used to communicate within the machine, no one
> else cares whether it changes. A file with narrow permissions is
> safer than trusting "localhost" restrictions.

Not really. For example, attacker exploits a vulnerability to briefly 
acquire root shell access. Attacker uses this to do two things: read the 
password and run "chattr +i ${file}". Now your attacker has the current 
password and has taken a step to prevent it from being changed.

-- 
Rich P.



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org