Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can't imagine that root is any faster. It's just a lot easier to run things as root vs splitting out separate processes with their own isolation mechanisms.

That the service runs as root isn't really the issue here. None of the attack relies on the abuse of some root capabilities, it's an authentication issue that abuses how the service works. Even if it were unprivileged somehow, this would still be the same impact.



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: