Subject: Re: NetBSD 1.5.2 default configuration
To: None <xs@kittenz.org>
From: M. Warner Losh <imp@village.org>
List: tech-security
Date: 02/03/2002 08:06:31
In message: <20020203121438.GA11083@meltdown.int.kittenz.org>
            xs@kittenz.org writes:
: > > This is for 'dump -n' to work.
: > 
: > Dump is another program that should be used only by people in group
: > operator.
: 
: Well, dump works (mostly) without any special privileges, so there
: isn't any real reason to restrict it to operator, imho.
: Plus restricting it to operator and keeping it setgid tty sounds like
: something that would make someone cry "give me ACLs!"

Dump can do this by forking wall and hacking wall to have -g for
delivering messages to a group.  FreeBSD did this a year or two ago,
and OpenBSD did it several years before that.

Warner