Comment Re: Nothing of value was added (Score 1) 119
They only happen after those large, visible and obviously stupid catastrophes. Not before. We will get them, but it may still take a while.
They only happen after those large, visible and obviously stupid catastrophes. Not before. We will get them, but it may still take a while.
That one is stupid and has been removed from any actual IT security standards AFAIK. Most advise against it in the supplemental materials. SOX is entirely the wrong place for something like that in addition.
This does illustrate another problem with IT security: Meaningless and sometimes harmful rituals instead of things that help.
Ah, I see. You do not know how file opening works on Linux. ">" opens files with O_TRUNC. Absolute standard c-library functionality. Nobody is out to get you.
Maybe there is a disconnect in the terminology. At least in Europe "regulation" usually means laws and "strong regulation" typically means laws with personal punishment provisions.
So, yes. I agree with you.
Yes. Same thing as if you do "rm -f" on the file, that is of you have aliased rm to normally ask. For some things you just have to know to be careful. If you do not, that is on you. It is not the fault of the tool.
A nice example of "lies, damned lies, and bad metrics". This one is so bad I would consider using it as an example of how to never do a security metric.
You read with autocorrect? Ok, in that case my apologies. "Well working" is a critical part of that statement. Badly working old things should definitely be replaced.
Strong regulation is required. It is just not sufficient, no argument from me about that.
The funny thing is that this has happened before in other engineering disciplines. It is always as cheap as possible and often cheaper than possible until some major catastrophe. For a nice instructive example, look up "San Francis Dam". Or "Titanic". Or countless others. There are tons of nice entries in the history of engineering failure.
What always helped in the end is liability, qualification requirements and enforceable quality standards. We will get these in IT as well, as the industry is fundamentally incapable of self-regulating.
Looks like I am totally obsolete. Of course you are perfectly right!
In other news, be afraid, be very afraid. Dumb people with nuclear weapons (figuratively or literally) are the new normal.
Hmm. Well, if your permission arrangement is this badly broken (root can spy on passwords getting typed in
That works as intended. The problem is on your side.
From the bash man-page: "If the file does not exist it is created; if it does exist it is truncated to zero size."
If you really want this to work differently, modify or write your own shell.
I remove sudo. The whole idea is fundamentally broken and I doubt it can even be made secure the way it is done. If you need root, be root.
No, that is not measurable. Unless you solved all the problems with testing code that have plagued the industry since its very existence? I am also dying to know how you want to measure the existence of not yet found security problems.
The coreutils are surprisingly complex.
Yes. That TOCTOU problem is a dead giveaway that the Rust coders involved are pretty incompetent regarding the task they are trying to do. I will let this age a few years before I will even consider using it.
If this is timesharing, give me my share right now.