[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc.
From: |
Lars Ingebrigtsen |
Subject: |
Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc. |
Date: |
Wed, 13 Sep 2017 22:11:05 +0200 |
User-agent: |
Gnus/5.13 (Gnus v5.13) Emacs/26.0.50 (gnu/linux) |
Paul Eggert <address@hidden> writes:
> It's an area where convenience and security collide.
What are the security implications of writing the file to the directory
if the user (interactively) types in that directory name?
> As a simple and dumb example, if people have "/ t m p RET" hardwired
> into their fingers, we could make an exception for "/tmp" without
> losing security. On real-world hosts the security problem can occur
> for subsidiary directories of /tmp, but not for /tmp itself.
The user can type anything, like "/home/larsi" and "/var/tmp" and the
behaviour should be the same across directories.
--
(domestic pets only, the antidote for overdose, milk.)
bloggy blog: http://lars.ingebrigtsen.no
- Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., (continued)
- Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Paul Eggert, 2017/09/12
- Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Stefan Monnier, 2017/09/14
- Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Eli Zaretskii, 2017/09/14
- Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Paul Eggert, 2017/09/14
- Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Eli Zaretskii, 2017/09/14
- Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Paul Eggert, 2017/09/15
- Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Eli Zaretskii, 2017/09/15
Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Eli Zaretskii, 2017/09/11
Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Lars Ingebrigtsen, 2017/09/13
Re: master 739593d 3/5: Make gnus-copy-file act like copy-file etc., Eli Zaretskii, 2017/09/13