From: | Dave Page <dpage(at)pgadmin(dot)org> |
---|---|
To: | Greg Stark <stark(at)mit(dot)edu> |
Cc: | Josh Berkus <josh(at)agliodbs(dot)com>, pgsql-hackers(at)postgresql(dot)org |
Subject: | Re: Switching to Homebrew as recommended Mac install? |
Date: | 2012-04-04 08:51:49 |
Message-ID: | CA+OCxoyMfhdm8OKFKOXSew5s9_MWO=h0JB+WxYszOygZp_o4-w@mail.gmail.com |
Views: | Raw Message | Whole Thread | Download mbox | Resend email |
Thread: | |
Lists: | pgsql-general pgsql-hackers |
On Tue, Apr 3, 2012 at 11:12 PM, Greg Stark <stark(at)mit(dot)edu> wrote:
> On Wed, Apr 4, 2012 at 1:19 AM, Dave Page <dpage(at)pgadmin(dot)org> wrote:
>> then, we're talking about making parts of the filesystem
>> world-writeable so it doesn't even matter if the user is running as an
>> admin for a trojan or some other nasty to attack the system.
>
> The argument is that a trojan or other nasty doesn't *need* to be
> admin to attack the system since it can just attack the user's account
> since that's where all the interesting data is anyways.
Isn't that what I said?
> But again, this is all beside the point. It's a judgement for Apple
> and Microsoft and individual administrators to make. We can't really
> start reconfiguring people's systems to use a different security model
> than they expect just because they've installed a database software --
> even if we think our security model makes more sense than the one
> their used to.
Exactly - which is why I was objecting to recommending a distribution
of PostgreSQL that came in a packaging system that we were told
changed /usr/local to be world writeable to avoid the use/annoyance of
the standard security measures on the platform.
--
Dave Page
Blog: http://pgsnake.blogspot.com
Twitter: @pgsnake
EnterpriseDB UK: http://www.enterprisedb.com
The Enterprise PostgreSQL Company
From | Date | Subject | |
---|---|---|---|
Next Message | Jon Nelson | 2012-04-04 13:50:15 | Re: views, queries, and locks |
Previous Message | Albe Laurenz | 2012-04-04 07:47:40 | Re: Unable to createlang |
From | Date | Subject | |
---|---|---|---|
Next Message | Joachim Wieland | 2012-04-04 09:03:01 | Re: parallel pg_dump |
Previous Message | Shigeru HANADA | 2012-04-04 06:43:34 | Re: pgsql_fdw, FDW for PostgreSQL server |