BLU Discuss list archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Discuss] memory management
- Subject: [Discuss] memory management
- From: invalid at pizzashack.org (Derek Martin)
- Date: Thu, 25 Jun 2015 14:37:56 -0500
- In-reply-to: <CAJFsZ=rsXdVZ2UnQxhF6sOxhXoyA1+=LTs-z3v_U9Vjdy1O3zw@mail.gmail.com>
- References: <558420D5.6090803@mattgillen.net> <55858DB0.4080709@mattgillen.net> <li6egl6t9pp.fsf@panix5.panix.com> <55863B7B.6020409@mattgillen.net> <55869BA6.4020709@blu.org> <CAJFsZ=qVaDpA0bbGjKy31Zd-Ws=FZ8QwuLN-KK71Xp23DWm9Cg@mail.gmail.com> <5586C7DE.8000700@gmail.com> <CAJFsZ=rsXdVZ2UnQxhF6sOxhXoyA1+=LTs-z3v_U9Vjdy1O3zw@mail.gmail.com>
On Sun, Jun 21, 2015 at 05:57:06PM +0200, Bill Bogstad wrote: > > xhost +SI:localuser:myffuser > > sudo -u ffuser /usr/bin/firefox > > xhost -SI:localuser:myffuser > > > > It's not an issue on a single user box; it's the same user (human) with a > > different UID. > > > > This is where I disagree. If it doesn't increase security over using the > same UID, why bother. It does though... it enables you to access the user's display without allowiong you to access their files (at least directly; it's possible there's some exploit but I'm not aware of one). > Second, if that user id has the privileges to pop up windows on the same X > server as my "real" user id; I might get spoofed, have my screen or even > possibly my keystrokes captured. The method I just posted will prevent that too. But it's extraordinarily unlikely that anything you're doing with your browser is going to result in such an attack. -- Derek D. Martin http://www.pizzashack.org/ GPG Key ID: 0xDFBEAD02 -=-=-=-=- This message is posted from an invalid address. Replying to it will result in undeliverable mail due to spam prevention. Sorry for the inconvenience.
- References:
- [Discuss] memory management
- From: me at mattgillen.net (Matthew Gillen)
- [Discuss] memory management
- From: me at mattgillen.net (Matthew Gillen)
- [Discuss] memory management
- From: smallm at panix.com (Mike Small)
- [Discuss] memory management
- From: me at mattgillen.net (Matthew Gillen)
- [Discuss] memory management
- From: gaf at blu.org (Jerry Feldman)
- [Discuss] memory management
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] memory management
- From: richard.pieri at gmail.com (Richard Pieri)
- [Discuss] memory management
- From: bogstad at pobox.com (Bill Bogstad)
- [Discuss] memory management
- Prev by Date: [Discuss] memory management
- Next by Date: [Discuss] memory management
- Previous by thread: [Discuss] memory management
- Next by thread: [Discuss] memory management
- Index(es):