Re: Musings about Usernames in adduser and Debian
On Thu, 5 Dec 2024 14:34:21 +0100, Alejandro Colomar <alx@kernel.org>
wrote:
>The best mitigation for those attacks is to ban the names altogether.
>IMO, setuid programs should not accept Unicode.
Oh, Bugs by Code. Dangerous. We should stop producing code completely.
No code, no bugs.
Neither adduser nor useradd are setuid.
--
----------------------------------------------------------------------------
Marc Haber | " Questions are the | Mailadresse im Header
Rhein-Neckar, DE | Beginning of Wisdom " |
Nordisch by Nature | Lt. Worf, TNG "Rightful Heir" | Fon: *49 6224 1600402
Reply to: