On Thu, 2018-02-01 at 17:05 -0500, Antoine Beaupre wrote:
[...]
> Note that the original systemd config also enables softlink
> protection:
> 
> https://salsa.debian.org/systemd-team/systemd/blob/master/sysctl.d/50-default.conf
>
> I'm not sure if that's also relevant here so I'd keep this to
> hardlinks for now to avoid unnecessary debate.
> 
> Incidentally, I wonder if we should remove the patch we have on the
> Debian kernels to change the defaults, and instead rely on the
> sysctl. I have added the kernel team in CC to have their input.

I would rather have the secure default specified in both places.  If we
unpatch the kernel then there's a risk of re-enabling link attacks in a
partial upgrade or backporting.

Ben.

-- 
Ben Hutchings
Every program is either trivial or else contains at least one bug

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to