Re: again security proposal

Albert D. Cahalan (acahalan@cs.uml.edu)
Thu, 1 Jan 1998 00:50:06 -0500 (EST)


Vladimir Volovich writes:

> Please, do not violate UNIX standards! Change your scripts better!
> We do not need a "security" section in kernel which will be nothing
> more than violation of standards and bloating the kernel source.
> This thread is not really a kernel issue, and should be solved from
> user space!

Wrong! How many times must I say this?

IT DOES NOT BREAK STANDARDS. I checked. You can go look for yourself,
in the Unix98 standard (version 2 of the Single Unix Specification).

As for fixing scripts... Sure, people have known that for 28 years.
One might assume all security holes would be fixed by now. :-)

I happen to find this extreme conservatism disturbing. Solaris has
beaten Linux to the stack-exec fix, even though the Linux patch was
available long ago! I'd say they took the Linux idea and just used it.
Innovation must die, right? This is sick.