Re: User NS usage and attack surface mitigation on debian

2021-06-20 Thread Ben Hutchings
On Tue, 2021-06-15 at 13:04 +0200, HolyTaint wrote: > I stumbled upon this answer from three years ago ( > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898446) > "User namespaces *are* enabled - but by default, they can only be > created by root". Note that this default has been changed in

Re: User NS usage and attack surface mitigation on debian

2021-06-16 Thread HolyTaint
Tue, 15 Jun 2021 13:04:54 +0200 HolyTaint : > I stumbled upon this answer from three years ago > (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898446) > "User namespaces *are* enabled - but by default, they can only be created by > root". > I need clarifications on that, cause I didn't quite

User NS usage and attack surface mitigation on debian

2021-06-15 Thread HolyTaint
I stumbled upon this answer from three years ago (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=898446) "User namespaces *are* enabled - but by default, they can only be created by root". I need clarifications on that, cause I didn't quite know how namespace management works. I experimented