enhance security via private TMP/TMPDIR by default

Matthew Miller mattdm at mattdm.org
Thu May 12 16:05:44 UTC 2005


On Thu, May 12, 2005 at 12:03:28PM -0400, Colin Walters wrote:
> > # For privacy and security, set temporary directories to ~/tmp on local
> There's actually been some work going on on giving each user their
> own /tmp namespace via the kernel's CLONE_NEWNS capability and a PAM
> module, AIUI.  To the system administrator this could appear
> as /tmp/<username>.  I think the problem is in getting later mounts to
> actually appear in the cloned namespace.

Ooh, that's kinda cool. This is easier, though. :) 

-- 
Matthew Miller           mattdm at mattdm.org        <http://www.mattdm.org/>
Boston University Linux      ------>                <http://linux.bu.edu/>
Current office temperature: 82 degrees Fahrenheit.




More information about the devel mailing list