From: Rene Scharfe <rene.scharfe@lsrfire.ath.cx>
To: Albert Cahalan <albert@users.sf.net>
Cc: Bodo Eggert <7eggert@gmx.de>,
linux-kernel mailing list <linux-kernel@vger.kernel.org>,
Andrew Morton OSDL <akpm@osdl.org>,
viro@parcelfarce.linux.theplanet.co.uk, pj@engr.sgi.com
Subject: Re: [PATCH][RFC] Make /proc/<pid> chmod'able
Date: Tue, 15 Mar 2005 22:18:17 +0100 [thread overview]
Message-ID: <42375119.3000506@lsrfire.ath.cx> (raw)
In-Reply-To: <1110854667.7893.203.camel@cube>
Albert Cahalan wrote:
> This really isn't about security. Privacy may be undesirable.
I agree, privacy is not security. My patch tries to enhance privacy
without giving up security.
You think losing the social pressure that comes with mutual surveillance
results in loss of security, I don't. Now I think Linux should support
both ways and those writing security policies should make the decision.
> With privacy comes anti-social behavior. Supposing that the
> users do get privacy, perhaps because the have paid for it:
>
> Xen, UML, VM, VMware, separate computers
>
> Going with separate computers is best. Don't forget to use
> network traffic control to keep users from being able to
> detect the network activity of other users.
That would work, but it requires a *lot* of administrative and computing
overhead. Note that "separate computers" alone is not sufficient
because most places with more than a few machines have some kind of
single signon and run SSH or similar.
[ps, w, top]
> They work like they do with a rootkit installed.
> Traditional behavior has been broken.
That's one way to put it; you could also say those tools now provide
enhanced privacy. ;)
I also think things have changed in the last few years. Since the
advent of special data processing laws privacy is taken more serious.
Privacy certainly was no real concern when UNIX was young. I also guess
it's a cultural thing, its importance being different from country to
country.
It's easily visible in the style of public toilets: in some contries you
have one big room with no walls in between where all men or women
merrily shit together, in other countries (like mine) every person can
lock himself into a private closet. Both ways work, there's nothing too
special about using a toilet, but I'm simply used to the privacy
provided by those thin walls. I assure you, I don't do anything evil in
there. :]
next prev parent reply other threads:[~2005-03-15 21:18 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-03-14 3:34 [PATCH][RFC] Make /proc/<pid> chmod'able Albert Cahalan
2005-03-14 9:42 ` Rene Scharfe
2005-03-14 16:13 ` Albert Cahalan
2005-03-14 23:08 ` Bodo Eggert
2005-03-15 2:44 ` Albert Cahalan
2005-03-15 10:51 ` Jonathan Sambrook
2005-03-15 14:31 ` Bodo Eggert
2005-03-15 15:29 ` Paul Jackson
2005-03-15 15:58 ` Albert Cahalan
2005-03-15 21:06 ` Bodo Eggert
2005-03-15 21:18 ` Rene Scharfe [this message]
2005-03-16 0:21 ` Kyle Moffett
2005-03-15 15:27 ` Rene Scharfe
2005-03-14 16:37 ` Pavel Machek
2005-03-16 2:39 ` [PATCH][RFC] /proc umask and gid [was: Make /proc/<pid> chmod'able] Rene Scharfe
2005-03-16 4:31 ` Albert Cahalan
2005-03-16 4:41 ` Albert Cahalan
2005-03-19 1:51 ` Rene Scharfe
-- strict thread matches above, loose matches on Subject: below --
2005-03-13 23:32 [PATCH][RFC] Make /proc/<pid> chmod'able Rene Scharfe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=42375119.3000506@lsrfire.ath.cx \
--to=rene.scharfe@lsrfire.ath.cx \
--cc=7eggert@gmx.de \
--cc=akpm@osdl.org \
--cc=albert@users.sf.net \
--cc=linux-kernel@vger.kernel.org \
--cc=pj@engr.sgi.com \
--cc=viro@parcelfarce.linux.theplanet.co.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox