From owner-freebsd-questions@FreeBSD.ORG Thu Feb 3 02:20:26 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 123C116A571 for ; Thu, 3 Feb 2005 02:20:26 +0000 (GMT) Received: from rproxy.gmail.com (rproxy.gmail.com [64.233.170.201]) by mx1.FreeBSD.org (Postfix) with ESMTP id 90E7543D5C for ; Thu, 3 Feb 2005 02:20:25 +0000 (GMT) (envelope-from gert.cuykens@gmail.com) Received: by rproxy.gmail.com with SMTP id f1so148479rne for ; Wed, 02 Feb 2005 18:20:24 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:references; b=EjfI/KlKCiHRSiYKG014QAUgEKebfs0R0O+VoKP1XGNZTq0MSK0iH98lp7GUh/ljfFFDA93h29LM4h0D8or/Pu3NsYBOYID1k1z931APCqQ/iKbkT5XLhJWjvGoaFdX10EJiW8Z7rsSce/FSoinM8+tWM6MD8XAJVodAYfehuoU= Received: by 10.38.90.39 with SMTP id n39mr207467rnb; Wed, 02 Feb 2005 18:19:34 -0800 (PST) Received: by 10.38.74.23 with HTTP; Wed, 2 Feb 2005 18:19:34 -0800 (PST) Message-ID: Date: Thu, 3 Feb 2005 03:19:34 +0100 From: Gert Cuykens To: Chris Hodgins In-Reply-To: <420174BC.8090609@cis.strath.ac.uk> Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit References: <20050202210526.GC77499@keyslapper.net> <42014E0A.5070003@mac.com> <20050202221851.GE77499@keyslapper.net> <20050202224322.GF77499@keyslapper.net> <20050202234814.GA24792@keyslapper.net> <420174BC.8090609@cis.strath.ac.uk> cc: freebsd-questions@freebsd.org Subject: Re: xhost +localhost X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Gert Cuykens List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 03 Feb 2005 02:20:26 -0000 > Don't want to be rude but do you have a specific reason for running > xscreensaver as root? > > Chris Well the reason is very simple actuale lets pretend we have a user gert. User gert has alot of pictures and music stuff phone numbers user gert dont want does things to be gone. Somebody hacks user gert because user gert uses a screensaver. And the hacker deletes all files. User gert is not happy because he lost everything. Do you think user gert gives a chit that the system was untouched because the hacker did not had root permission ? For me its wrong to think user accounts are not importend because they do for the average window xp single user. They dont care about viruses infection on there system reinstalling everything they care about there files. So if sreensaver is a securty risc as root i doesnt mean its not a security risck for a user account. The only differens between a root and user should be that users can not read or mess with other users files. The security sould be EXACTLY the same. So if root can not run a screensaver then the users can also not run a screensaver.