Hacker Newsnew | past | comments | ask | show | jobs | submit | chuso's commentslogin

It's the same with Gentoo, setuid binaries are installed without read permission.

But modifying a setuid binary is just the demo exploit that was published with the vulnerability disclosure. The vulnerability actually allows modifying four bytes in any readable file. That means system configuration files, other binaries intended to be run by root, libraries... It's not limited to modifying setuid binaries.


Break it often and don't fix it.


AFAIK, GnuPG and S/MIME only encrypt message body, but not its headers such as sender, receipt, date, subject, ...


Yes that's true


... email account passwords ...


Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: