Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.devel > #108716
| From | Matthew Garrett <mjg59@srcf.ucam.org> |
|---|---|
| Newsgroups | linux.debian.devel |
| Subject | Re: HFS/HFS+ are insecure |
| Date | 2023-07-22 10:40 +0200 |
| Message-ID | <GUgjD-1VFX-5@gated-at.bofh.it> (permalink) |
| References | (2 earlier) <GTVoS-1ICx-7@gated-at.bofh.it> <GTVyx-1IFz-15@gated-at.bofh.it> <GUfxf-1V9t-11@gated-at.bofh.it> <GUfGW-1Vd5-11@gated-at.bofh.it> <GUg9X-1VCN-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Sat, Jul 22, 2023 at 10:21:47AM +0200, Jonas Smedegaard wrote: > Quoting Matthew Garrett (2023-07-22 09:54:59) > > On Sat, Jul 22, 2023 at 03:41:58PM +0800, Paul Wise wrote: > > > Disabling auto-mounting and for manual GUI mounts, requesting users > > > confirm they trust the filesystem they are mounting would avoid that > > > as much as is reasonably possible without entirely deleting the code > > > and without breaking the use-cases of people who need the filesystem > > > code. > > > > When is a user going to plug in a USB stick and *not* click that > > button? > > When the user had plugged in a coworker's phone they were asked to please > charge. We're a long way down the social engineering chain there - I think that turns into a question of how many people are going to benefit from not automounting because of that case vs the number who benefit from the convenience under normal circumstances.
Back to linux.debian.devel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#1041552: HFS/HFS+ are insecure Marco d'Itri <md@Linux.IT> - 2023-07-20 20:10 +0200
Re: HFS/HFS+ are insecure Matthew Garrett <mjg59@srcf.ucam.org> - 2023-07-21 10:30 +0200
Re: HFS/HFS+ are insecure Marco d'Itri <md@Linux.IT> - 2023-07-21 11:00 +0200
Re: HFS/HFS+ are insecure Magissia <debianlist@magissia.com> - 2023-07-21 11:10 +0200
Re: HFS/HFS+ are insecure Martin Steigerwald <martin@lichtvoll.de> - 2023-07-21 12:10 +0200
Re: HFS/HFS+ are insecure Bastien Roucariès <rouca@debian.org> - 2023-07-21 13:00 +0200
Re: HFS/HFS+ are insecure Bastien Roucariès <rouca@debian.org> - 2023-07-21 13:10 +0200
Re: HFS/HFS+ are insecure Matthew Garrett <mjg59@srcf.ucam.org> - 2023-07-21 19:40 +0200
Re: HFS/HFS+ are insecure Ben Hutchings <ben@decadent.org.uk> - 2023-07-23 02:40 +0200
Re: HFS/HFS+ are insecure Magissia <debianlist@magissia.com> - 2023-07-21 11:20 +0200
Re: HFS/HFS+ are insecure Bastien Roucariès <rouca@debian.org> - 2023-07-21 12:00 +0200
Re: HFS/HFS+ are insecure Marco d'Itri <md@Linux.IT> - 2023-07-21 12:20 +0200
Re: HFS/HFS+ are insecure Bastien Roucariès <rouca@debian.org> - 2023-07-21 12:30 +0200
Re: HFS/HFS+ are insecure Bastien Roucariès <rouca@debian.org> - 2023-07-21 13:10 +0200
Re: HFS/HFS+ are insecure Paul Wise <pabs@debian.org> - 2023-07-22 09:50 +0200
Re: HFS/HFS+ are insecure Matthew Garrett <mjg59@srcf.ucam.org> - 2023-07-22 10:00 +0200
Re: HFS/HFS+ are insecure Jonas Smedegaard <jonas@jones.dk> - 2023-07-22 10:30 +0200
Re: HFS/HFS+ are insecure Matthew Garrett <mjg59@srcf.ucam.org> - 2023-07-22 10:40 +0200
Re: HFS/HFS+ are insecure Jeremy Stanley <fungi@yuggoth.org> - 2023-07-22 14:50 +0200
Re: HFS/HFS+ are insecure Paul Wise <pabs@debian.org> - 2023-07-25 06:40 +0200
Re: HFS/HFS+ are insecure Paul Wise <pabs@debian.org> - 2023-07-25 06:30 +0200
Re: HFS/HFS+ are insecure Bastien Roucariès <rouca@debian.org> - 2023-07-21 12:20 +0200
Re: HFS/HFS+ are insecure Bastien Roucariès <bastien.roucaries@cyu.fr> - 2023-07-21 12:30 +0200
Re: HFS/HFS+ are insecure Seth Arnold <seth.arnold@canonical.com> - 2023-07-21 23:20 +0200
csiph-web