On Thu, 2018-02-01 at 17:05 -0500, Antoine Beaupre wrote: [...] > Note that the original systemd config also enables softlink > protection: > > https://salsa.debian.org/systemd-team/systemd/blob/master/sysctl.d/50-default.conf > > I'm not sure if that's also relevant here so I'd keep this to > hardlinks for now to avoid unnecessary debate. > > Incidentally, I wonder if we should remove the patch we have on the > Debian kernels to change the defaults, and instead rely on the > sysctl. I have added the kernel team in CC to have their input.
I would rather have the secure default specified in both places. If we unpatch the kernel then there's a risk of re-enabling link attacks in a partial upgrade or backporting. Ben. -- Ben Hutchings Every program is either trivial or else contains at least one bug
signature.asc
Description: This is a digitally signed message part

