[PATCH 1/4] added SECURITY_TIOCSTI_RESTRICT kernel config
From: Alan Cox <hidden>
Date: 2017-04-18 14:24:44
Also in:
lkml
From: Alan Cox <hidden>
Date: 2017-04-18 14:24:44
Also in:
lkml
Since tty sessions are usually separated by different users, how would they have the same one and yet need something like this? Also, why not put this in the tty config section?
The normal attack use case people argue about is a rogue process on the users machine sitting there waiting until the user has logged in to a remote machine and is idle and then doing stuff. Attackers of course don't bother doing that because it's easier to get the user to run a different ssh client instead. Alan -- To unsubscribe from this list: send the line "unsubscribe linux-security-module" in the body of a message to majordomo at vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html