oss-sec mailing list archives

Re: TTY pushback vulnerabilities / TIOCSTI


From: Hanno Böck <hanno () hboeck de>
Date: Wed, 15 Mar 2023 10:40:35 +0100

On Wed, 15 Mar 2023 20:03:11 +1100 (EST)
Dave Horsfall <dave () horsfall org> wrote:

I hate tossing out functionality; would you not make it a privileged 
operation instead?

From a security perspective tossing out functionality is the better
option compared to restricting access. If there is practically no use
of that functionality and it's mostly a security risk, then removing it
is the right choice.

Reducing complexity is a good principle for IT security.

-- 
Hanno Böck
https://hboeck.de/


Current thread: