Subject: Re: Removing dm(1)
To: None <tech-security@NetBSD.ORG>
From: Ty Sarna <tsarna@endicor.com>
List: tech-security
Date: 11/18/1997 23:20:19
In article <Pine.NEB.3.96.971118135544.22439A-100000@cynic.portal.ca> you write:
> Perhaps I need to summarise my argument in a different way. Why
> don't you tell me which points in particular you disagree with.
> 
> 1. The binaries of the games are easily available, and can be
> downloaded and run by normal users.

Not necessarily. Not on a captive-shell system, for example, if one
wants to allow capive users to run games (which would obviously be
dangeous right now, but there's noting inherently wrong with it.

Your points 2&3 follow from one, and thus also aren't universally true.

In fact, I would (if I had more confidence in the games) allow (captive)
users on one system here to play games, and dm would be useful in that
event.  In fact, I'd like to see an additional feature in dm, even.

> This doesn't leave a whole lot of machines out there on which dm
> is useful, does it?

Not many pc532's out there on which NetBSD is useful, either.
I don't think we should remove it, even so.

If you don't want dm, don't use it. Or better yet, if you're worried
about security, delete the games from your system for now, or fix them.
I think removing dm from NetBSD is a bit heavy-handed, though.