all messages for Emacs-related lists mirrored at yhetil.org
 help / color / mirror / code / Atom feed
* Closing a privilege escalation
@ 2018-04-25  1:09 Richard Stallman
  2018-04-25  1:18 ` Noam Postavsky
                   ` (3 more replies)
  0 siblings, 4 replies; 19+ messages in thread
From: Richard Stallman @ 2018-04-25  1:09 UTC (permalink / raw
  To: emacs-devel

[[[ To any NSA and FBI agents reading my email: please consider    ]]]
[[[ whether defending the US Constitution against all enemies,     ]]]
[[[ foreign or domestic, requires you to follow Snowden's example. ]]]

With some arguments, emacs started inside sudo will run the user's own
.emacs file rather than root's.  This creates a known vulnerability
for privilege escalation.

I propose a feature to fix the vulnerability:

  For sudo-authorized users, require .emacs (and other Emacs startup
  files and directories) to be owned by root.

This won't be a big hassle for them, since
these users can sudo to edit their root-owned files.

Do people see any problem with this?

-- 
Dr Richard Stallman
President, Free Software Foundation (https://gnu.org, https://fsf.org)
Internet Hall-of-Famer (https://internethalloffame.org)
Skype: No way! See https://stallman.org/skype.html.




^ permalink raw reply	[flat|nested] 19+ messages in thread

end of thread, other threads:[~2018-04-27 15:57 UTC | newest]

Thread overview: 19+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-04-25  1:09 Closing a privilege escalation Richard Stallman
2018-04-25  1:18 ` Noam Postavsky
2018-04-25 22:40   ` Richard Stallman
2018-04-25  1:29 ` Lars Ingebrigtsen
2018-04-25 22:40   ` Richard Stallman
2018-04-26  7:20     ` Lars Ingebrigtsen
2018-04-26  7:52       ` Lars Ingebrigtsen
2018-04-26 21:05       ` Richard Stallman
2018-04-26 21:26         ` Tim Cross
2018-04-27 15:57           ` Richard Stallman
2018-04-27  9:50         ` Marcin Borkowski
2018-04-27 14:29           ` Clément Pit-Claudel
2018-04-25 15:25 ` Davis Herring
2018-04-25 16:47 ` Glenn Morris
2018-04-25 17:09   ` Stefan Monnier
2018-04-25 17:12     ` Stefan Monnier
2018-04-25 17:55     ` Paul Eggert
2018-04-26 21:01     ` Richard Stallman
2018-04-25 17:10   ` Søren Pilgård

Code repositories for project(s) associated with this external index

	https://git.savannah.gnu.org/cgit/emacs.git
	https://git.savannah.gnu.org/cgit/emacs/org-mode.git

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.