[14567] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: NCipher Takes Hardware Security To Network Level

daemon@ATHENA.MIT.EDU (Dave Howe)
Tue Oct 7 16:17:07 2003

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
From: "Dave Howe" <DaveHowe@gmx.co.uk>
To: "Email List: Cryptography" <cryptography@metzdowd.com>
Date: Tue, 7 Oct 2003 18:49:36 +0100

Peter Gutmann wrote:
> Uhh, so you're avoiding privilege escalation attacks by having
> everyone run as root, from which you couldn't escalate if you wanted
> to.
Indeed so.
"What do you do to prevent ordinary users from abusing access to the
software"
"we don't allow them on - only admins can use this machine"
"but ordinary users will *have* to use this machine"
"yes, but they will be admins while they do it"
"oh, ok then" <sound of rubber stamp being applied>

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post