Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

On Linux, ptrace permissions can be restricted [0] and some distributions do this by default.

Whether this provides any meaningful security is questionable unless you pair it with filesystem isolation to prevent malicious programs from modifying config files / bashrc / etc. Meanwhile it does make legit uses of ptrace more annoying.

[0] https://www.kernel.org/doc/Documentation/security/Yama.txt



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: