David Uhden Collado <[email protected]> wrote:

> Theo de Raadt wrote:
> >> big clue is having file access and network access in the same process.
> >    ^^^ Correct, because 90% of the attack surface remains if a
> > process
> >    has both of those.
> 
> Some developers are happy as long as the program works, even if the
> security design is poor. You see the same thing on Linux, where
> AppArmor, SELinux, and similar tools are added around applications
> that still keep filesystem and network access in the same process.
> 
> It seems they kept everything in one process and one configuration
> file simply because it was easier than redesigning the application. I
> do not understand the obsession with having fewer files or
> processes. It does not meaningfully reduce compile time or resource
> usage, and it offers no security benefit. Proper privilege separation,
> on the other hand, can greatly reduce the attack surface.

You are telling me?  Wow...

Reply via email to