From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id ; Tue, 14 Aug 2001 14:40:23 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id ; Tue, 14 Aug 2001 14:40:07 -0400 Received: from 64-42-29-14.atgi.net ([64.42.29.14]:5905 "HELO mail.clouddancer.com") by vger.kernel.org with SMTP id ; Tue, 14 Aug 2001 14:39:39 -0400 To: linux-kernel@vger.kernel.org Subject: Re: Is there something that can be done against this ??? In-Reply-To: <9lb8vp$10q$1@ns1.clouddancer.com> In-Reply-To: <3B7924C7.31923A8@trader.com> <9lb8vp$10q$1@ns1.clouddancer.com> Reply-To: klink@clouddancer.com Message-Id: <20010814163452.3046E783F5@mail.clouddancer.com> Date: Tue, 14 Aug 2001 09:34:52 -0700 (PDT) From: klink@clouddancer.com (Colonel) Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org In clouddancer.list.kernel, you wrote: > >David Schwartz wrote: >> >> > The question is not : "is this script dangerous ?", >> > but "are you ready to blindly execute a shell script >> > (or any program) that you receive in your mail ?". >> >> Sure, as a user created solely for that purpose, it should be entirely >> safe. >> > >How many users are there that use a specific user account to read >their emails on their Linux workstation ? >I don't, I use my account to read mails, write documents, >develop programs,etc. So even if a malicious program does >not do any arm to the system, it can at least destroy or corrupt my >own files and I will loose time restoru=ing from last backup and >rebuilding recently modified files. Anybody that can think probably does that. First they think that setting up a test user takes a few seconds, then they think that restoring from backup takes at least 100x longer.... -- Windows 2001: "I'm sorry Dave ... I'm afraid I can't do that."