Secure Coding mailing list archives
how far we still need to go
From: BlueBoar at thievco.com (Blue Boar)
Date: Wed, 25 Jul 2007 15:18:28 -0700
William L. Anderson wrote:
I am flabbergasted. When I first encountered Unix in 1983 I was taught that you always run as an ordinary user, and only use admin (root) privileges when needed. If OS X developers are running as admin, and building and testing their products as admin, well ... I'm still in shock. And I weep for the species.
Are you confusing the Mac specifics? "Admin" on OS X is not the same as root. Members of the Admin group can elevate privs to do things as the equivalent of root, and the Admin group can write to /Applications. The app in question could improve, of course, but the fact the Admin has so much power and that the first user you create is a member of that group is the fault of OS X. (At least, that's the way it worked not too long ago, Apple does seem to occasionally fix these things over time.) BB
Current thread:
- how far we still need to go William L. Anderson (Jul 25)
- how far we still need to go Steven M. Christey (Jul 25)
- how far we still need to go Kenneth Van Wyk (Jul 25)
- how far we still need to go Blue Boar (Jul 25)
- how far we still need to go William L. Anderson (Jul 25)
- how far we still need to go Dinis Cruz (Jul 25)
- how far we still need to go ljknews (Jul 25)
- how far we still need to go McGovern, James F (HTSC, IT) (Aug 28)
- how far we still need to go ljknews (Jul 25)