> Paranoia is not synonymous with security, nor is it synonymous > with "privacy." > > Hacking ps to fix a security problem in ppp is not the solution: > fixing ppp is. ps(1)'s -a and -e flags were implemented for a > reason; to remove them is de-evolutionary. Agreed, but one could associate the ability as an unprivledged user to read *other* users' environment variables with the finger(1) bug that allowed users to read arbitraty files (or the sendmail uuencode bug, or ...). The only difference is that the target is not a file, it is an environment variable. There is a reason I make my shell's rc files mode 0700 and have a umask of 077, and paranoia/security laziness are *not* why. :) Scott -- scottat_private UNIX Sysadmin, CyberSource (ext. 6093) "My manager, after having poked his head into my area for the 10th time today, said, `I just can never understand how sysadmins can work effectively with people breathing down their necks.'" - a friend
This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:12:38 PDT