Re: security thing



In alt.os.linux PTM <ptmusta@xxxxxxxxxxxxxxxxxx>:
Is there any way to set Linux so, that an user can see only her own home
directory but nothing else. I find annoying that the system files can be
seen by anybody. I find no reason, why She should see for example the
/etc directory.

How should "ls -l" work if the system can't map UID/GID via
worldwide readable passwd/groups? Of course you could setup a
chroot chage for each user...

Another thing is that now she can see the directories of other users, if
they have not set the visibility. This is a kind of backward behaviour.

Change permissions of users $HOME if you want, just a single
command 'man chmod'.

In my mind everything personal should be secured until you give other
users rights to read it. This is how we behave in real life.

Can be configured through /etc/login.defs via umask setting
or/and system wide profile. Iirc 'useradd' and probably
associated tools will honor this while creating users $HOME.

Some distro setup new users $HOME 0700 which does what you ask
and set umask accordingly.

One reason for many default permissions might be unix was
developed by researchers for researchers, to make sharing
information easy. Not to restrict users in the first place.

However, it is up to you to simply change those defaults to your
needs, which can be done through automatic installation
procedures such as kickstart (RH/Fedora) if you like.

--
Michael Heiming (X-PGP-Sig > GPG-Key ID: EDD27B94)
mail: echo zvpunry@xxxxxxxxxx | perl -pe 'y/a-z/n-za-m/'
#bofh excuse 187: Reformatting Page. Wait...
.



Relevant Pages

  • Re: where is the man pages path set in OS X?
    ... you say there is no reason while giving one. ... > reason to not fiddle around with the system is that root newbies tend to ... I use Emacs to edit system files, ... Installing stuff into /bin and /usr/bin is not necessarily installing ...
    (comp.sys.mac.system)
  • Re: folder ownership rights etc.
    ... one "takes ownership" of an item, ... which confers power to change permissions, ... There's no reason for XP to be more ... |> Now I will copy selected folders fron the Toshiba drive to my main ...
    (microsoft.public.windowsxp.general)
  • Re: sfc /scannow
    ... >It is normally used to check for damaged or missing ... system files. ... good reason. ... after the sfc my menu icon for windows messenger is no ...
    (microsoft.public.windowsxp.general)
  • Re: security thing
    ... I find annoying that the system files can be ... I find no reason, why She should see for example the ... users rights to read it. ... In real life, we trust each other not to pry into each other's lives. ...
    (alt.os.linux)
  • Re: ReadFile Question
    ... In article, Rimvydas Paulavicius wrote: ... > Simple Windows Cut & Paste does. ... What's the reason? ... Can you name some specific system files that show this problem? ...
    (borland.public.delphi.nativeapi)