Re: [sage-devel] Sage security

2012-03-04 Thread Robert Bradshaw
On Sat, Mar 3, 2012 at 7:59 AM, Jeroen Demeyer wrote: > On 2012-03-02 18:31, Jan Groenewald wrote: >> Are all notebook users running as the same sage user? > Yes. > >> How could sage users be separated? > We could map Sage notebook users to Unix separate Unix users, but then > the Sage notebook se

Re: [sage-devel] Sage security

2012-03-03 Thread Jeroen Demeyer
On 2012-03-02 18:31, Jan Groenewald wrote: > Are all notebook users running as the same sage user? Yes. > How could sage users be separated? We could map Sage notebook users to Unix separate Unix users, but then the Sage notebook server would need to run as root (as least partially). -- To post

Re: [sage-devel] Sage security

2012-03-02 Thread Jan Groenewald
Hi On 2 March 2012 09:03, Robert Bradshaw wrote: > Sage is as secure as bash (+ compilers). If you want to run arbitrary > bash scripts, let other people run their bash scripts, or set up a web > interface for others to running bash scripts, then you should get your > security from another level

Re: [sage-devel] Sage security

2012-03-02 Thread Robert Bradshaw
Sage is as secure as bash (+ compilers). If you want to run arbitrary bash scripts, let other people run their bash scripts, or set up a web interface for others to running bash scripts, then you should get your security from another level (limited accounts, jails, virtual machines, etc.) One can

[sage-devel] Sage security

2012-03-01 Thread Jeroen Demeyer
On 2012-02-29 22:56, Jan Groenewald wrote: > Sage now has to watch the security updates for each component. Sage is totally insecure and watching security updates isn't going to solve this problem. -- To post to this group, send an email to sage-devel@googlegroups.com To unsubscribe from this gro