|
From: Bruce S. <bw...@ar...> - 2008-04-10 12:48:34
|
> My worry about using unionfs is giving a possible intruder the option > to 'overwrite' files. > I have to admit I really don't know much about unionfs/aufs, but we > need to make sure we keep at least the same level of security. At the moment I'm only talking about making the change to /etc. All the changes would still be in memory, so we're not really losing any security, or doing anything different in that sense. It may be a problem if we start using it for the read-only filesystem on the CD (i.e. /usr). I'm not sure we should do that either. If a user wants to manually set that up for themselves, that's their problem. We can't force people to keep their system secure. - BS |