guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: We should disable dmesg for unprivileged users by default


From: Ricardo Wurmus
Subject: Re: We should disable dmesg for unprivileged users by default
Date: Mon, 15 Jul 2019 14:48:58 +0200
User-agent: mu4e 1.2.0; emacs 26.2

Ludovic Courtès <address@hidden> writes:

> Hi,
>
> Alex Vong <address@hidden> skribis:
>
>> I think we should set /proc/sys/kernel/dmesg_restrict to 1 by default to
>> prevent unprivileged users from reading the kernel ring buffer (since it
>> could expose sensitive information about the system).
>
> We could have a ‘dmesg-restrict’ service that would write to that file
> as part of system activation, and we’d add it to ‘%base-packages’.
> WDYT?

This sounds good!

-- 
Ricardo




reply via email to

[Prev in Thread] Current Thread [Next in Thread]