Subject: Re: Separate /usr, etc...
To: Chuck Yerkes <chuck+nbsd@2003.snew.com>
From: Greg A. Woods <woods@weird.com>
List: current-users
Date: 12/17/2002 18:02:43
On Monday, 16 December 2002 at 14:43:36 -0800, Chuck Yerkes wrote:
>
> I'm a very strong advocate of making /usr separate because I
> mount it read-only.  In fact, except for root, if it's got
> a binary on it, it's RO.  If it's got data, it's mounted
> noexec, nosuid, nodev.  Several reasons.  And I've built machines
> where the binaries are on disks PINNED read-only (trojan that!).

It's far easier to get much better read-only coverage of your sensitive
files using the immutable flag -- then you can protect scripts and
binaries and static data files on the root FS too.

-- 
								Greg A. Woods

+1 416 218-0098;            <g.a.woods@ieee.org>;           <woods@robohack.ca>
Planix, Inc. <woods@planix.com>; VE3TCP; Secrets of the Weird <woods@weird.com>