Re: Open then gates

2010-05-15 Thread Robert Klotzner
On Saturday 15 May 2010 13:47:43 Christoph Anton Mitterer wrote: > On Sat, 2010-05-15 at 13:22 +0200, Michael Biebl wrote: > > It just shows how such stuff can completely undermine security, and one > even haven't thought that this would possible. This applies to any change you make to a piece o

Re: Bug#581729: [SQUEEZE] Document the umask change for new installs

2010-05-15 Thread Robert Klotzner
On Saturday 15 May 2010 13:50:50 Christoph Anton Mitterer wrote: > On Sat, 2010-05-15 at 13:45 +0200, Holger Levsen wrote: > > This paragraph should be accompanied by something like: > > > > Instead of adding users to other users private groups (which has issues > > as explained above) it is recomm

Re: Open then gates

2010-05-15 Thread Robert Klotzner
> You need to explain clearly how the umask of 0002 is insecure. If you > have members in your user private group, then your group isn't private, > is it? UPG is designed to NOT have anyone else in your group except you. > So, adding the write bit on the group mode does not affect security in > the