Author: sqweeksqweek Date: Aug 20, 2008 11:10
On Wed, Aug 20, 2008 at 8:56 PM, Eris Discordia
gmail.com> wrote:
>> No. Private namespaces.
>
> And how does that solve the problem of whom to trust with mounting?
You don't care who mounts what where, because the rest of the system
doesn't notice the namespace change. But it sounds like what you're
really talking about is who to trust with device access, so lets roll
with that.
> Or with configuring a network interface?
As Pietro demonstrated, no interface configuration is necessary here.
> If someone has access to, say, eth0 then
> they have access to eth0. No amount of private namespaces keeps them from
> reading everything that goes through eth0, including other users'
> unencrypted traffic.
|