|
|
|
|
|
by js2
41 days ago
|
|
Why are you sure of that? I wouldn't design a critical system that relied on the difference between root and non-root accounts to protect private keys. I would design a system assuming the attacker can trivially escalate to root privilege. Because historically you just cannot rely on the difference. LPE attacks simply happen on too regular a basis. |
|
https://blog.nelhage.com/2010/12/cve-2010-4258-from-dos-to-p...