![]() |
#16 |
Omnivorous
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,283
Karma: 27978909
Join Date: Feb 2008
Location: Rural NW Oregon
Device: Kindle Voyage, Kindle Fire HD, Kindle 3, KPW1
|
I'm going to repeat what I said on the other "The Sky Is Falling" thread.
Local exploits are pretty meaningless to 99% (I don't dare say 100%) of home Linux users. If I have physical access to your machine and the drives are not encrypted, that machine is mine. It's as simple as a flash drive with a live linux distribution. I'm not going to get worked up over a possible local security problem in Calibre. It's good to be aware of problems. But in this case, the Sky is *not* falling. |
![]() |
![]() |
![]() |
#17 | |
Linux User
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,282
Karma: 6123806
Join Date: Sep 2010
Location: Heidelberg, Germany
Device: none
|
Quote:
Security is one of the reasons why people choose Linux. However it's only secure as long as every security issue, no matter how small, is taken very seriously and fixed soonest possible. You can't talk an issue like this away - you can only fix it. |
|
![]() |
![]() |
Advert | |
|
![]() |
#18 | ||
creator of calibre
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,378
Karma: 27230406
Join Date: Oct 2006
Location: Mumbai, India
Device: Various
|
Quote:
Quote:
|
||
![]() |
![]() |
![]() |
#19 | |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
Quote:
|
|
![]() |
![]() |
![]() |
#20 | |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 1,337
Karma: 123455
Join Date: Apr 2009
Location: Malaysia
Device: PRS-650, iPhone
|
Quote:
Last edited by ldolse; 11-04-2011 at 01:11 PM. |
|
![]() |
![]() |
Advert | |
|
![]() |
#21 |
Zealot
![]() ![]() ![]() ![]() Posts: 106
Karma: 348
Join Date: Dec 2006
|
You should always assume the trust is there, users are idiots. A developer should take that into account and not allow their project to be used to take advantage of a users system.
|
![]() |
![]() |
![]() |
#22 | |
Omnivorous
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 3,283
Karma: 27978909
Join Date: Feb 2008
Location: Rural NW Oregon
Device: Kindle Voyage, Kindle Fire HD, Kindle 3, KPW1
|
Quote:
If I worried about every *minor* security problem there was with Linux and it's applications I'd never turn my machine on and certainly never get online. I understand the issues. Most of the people here understand the issues. Can we drop this and move on? ![]() |
|
![]() |
![]() |
![]() |
#23 |
Well trained by Cats
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 31,079
Karma: 60358908
Join Date: Aug 2009
Location: The Central Coast of California
Device: Kobo Libra2,Kobo Aura2v1, K4NT(Fixed: New Bat.), Galaxy Tab A
|
Most of the Windows in my house are large enough to climb through and attack my Linux systems.
Large windows = a real Security vulnerability and must be fixed immediately ![]() |
![]() |
![]() |
![]() |
#24 |
onlinenewsreader.net
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 328
Karma: 10143
Join Date: Dec 2009
Location: Phoenix, AZ & Victoria, BC
Device: Kindle 3, Kindle Fire, IPad3, iPhone4, Playbook, HTC Inspire
|
|
![]() |
![]() |
![]() |
#25 |
Sigil & calibre developer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,487
Karma: 1063785
Join Date: Jan 2009
Location: Florida, USA
Device: Nook STR
|
The mount helper has been removed, a decision I'm in agreement with and believe is the correct course of action.
|
![]() |
![]() |
![]() |
#26 |
(he/him/his)
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 12,296
Karma: 80074820
Join Date: Jul 2010
Location: Sunshine Coast, BC
Device: Oasis (Gen3),Paperwhite (Gen10), Voyage, Paperwhite(orig), iPad Air M3
|
I got my start in this business as a UNIX system administrator. I know what root is. And even though I've been off UNIX for years, and mostly write about Windows now, I'll state unequivocally that if I have physical access to your machine, I own it, short of encrypted system disks (and even those, under some highly technical situations). So a "local only" exploit just really doesn't get me excited. Yes, certainly, it should get fixed. But let's not get our knickers in a twist.
|
![]() |
![]() |
![]() |
#27 | |
Linux User
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,282
Karma: 6123806
Join Date: Sep 2010
Location: Heidelberg, Germany
Device: none
|
Quote:
Gentoo already removed it (replaced in favour of Debian's alternative). As a result the Gentoo package now pulls in udisks as a dependency. I tested it and it works fine for me. For Gentoo users who didn't have udisks installed before that, it's an improvement in both security and usability. |
|
![]() |
![]() |
![]() |
#28 |
Wizard
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 4,337
Karma: 4000000
Join Date: Oct 2008
Location: Paris
Device: Cybooks; Sony PRS-T1
|
|
![]() |
![]() |
![]() |
#29 |
Sigil & calibre developer
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 2,487
Karma: 1063785
Join Date: Jan 2009
Location: Florida, USA
Device: Nook STR
|
If you use a distro that includes udisks (Fedora, Ubuntu, Debian, Suse...), nothing. Ubuntu 10.04 Lucid was the first Ubuntu release with udisks support. If you use an old distro then auto mounting and unmounting of devices no longer works.
|
![]() |
![]() |
![]() |
#30 | |
creator of calibre
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Posts: 45,378
Karma: 27230406
Join Date: Oct 2006
Location: Mumbai, India
Device: Various
|
Quote:
It might actually work if you mount it manually even after starting calibre, but that is not very reliable. |
|
![]() |
![]() |
![]() |
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Calibre loads books into Root of SD card, help please | vitalichka | Library Management | 4 | 03-06-2011 06:47 PM |
Calibre on linux: root password for unmounting? | mhomann | Devices | 14 | 02-05-2011 11:26 AM |
Adobe Reader 9 new exploit in the wild | doctorow | News | 2 | 02-20-2009 03:38 PM |
iLiad Huge exploit found in 2.7 | arivero | iRex Developer's Corner | 86 | 11-26-2006 04:49 PM |
Serious exploit in Greasemonkey 0.4 | Alexander Turcic | Lounge | 2 | 07-19-2005 04:59 AM |