Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Defense works in layers. Punching through one of those layers makes securty worse even if that layer was not the first or the primary defense.

The problem here is that a priviledged process (and yes, a process that has access to Port 80 and 443 is priviledged even if it doesn't run as root) gives unauthenticated control to less priviledged processes.

With good security design you don't lock things down as needed but instead start fully locked down and open up only the accesss you really need.



> With good security design you don't lock things down as needed but instead start fully locked down and open up only the accesss you really need.

This. @mholt what we're arguing for is just to have secure defaults.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: