TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Private Home Directories for Ubuntu 21.04

110 pointsby oedmarapabout 4 years ago

14 comments

ohaziabout 4 years ago
To me, user accounts have always seemed like the more reasonable approach to sandboxing vs. cloning the universe to run a single program in a container.<p>Most of my systems have a user for myself, and one or two other users like `sketchy` or `test` or something for programs that I trust enough to run, but don&#x27;t trust enough to not fuck up my home directory in some way (including modifying startup scripts, which IMHO should probably require sudo to edit, even for a normal user).<p>If the program is <i>really</i> sketchy and you&#x27;re worried about it doing something like exfiltrating ~&#x2F;Documents&#x2F;taxes, then private home directories would definitely seem like a good default. You can always have an explicitly shared area like &#x2F;home&#x2F;shared&#x2F;$user that defaults to public.
评论 #26789882 未加载
评论 #26787977 未加载
评论 #26790994 未加载
评论 #26788164 未加载
bombcarabout 4 years ago
This is just changing the default permissions on a home directory -not a more complicated encrypted&#x2F;systemd setup I thought it would be.
评论 #26786627 未加载
评论 #26787009 未加载
评论 #26787550 未加载
评论 #26787469 未加载
alamortsubiteabout 4 years ago
Makes sense to me, but I&#x27;d be much more excited to go back to not having the snap directory shoved in my face.
评论 #26789792 未加载
评论 #26787914 未加载
评论 #26786761 未加载
评论 #26788935 未加载
评论 #26787224 未加载
yrroabout 4 years ago
I wish such announcements would include a reference to the bug tracker where the change was discussed:<p><a href="https:&#x2F;&#x2F;bugs.launchpad.net&#x2F;ubuntu&#x2F;+source&#x2F;adduser&#x2F;+bug&#x2F;48734" rel="nofollow">https:&#x2F;&#x2F;bugs.launchpad.net&#x2F;ubuntu&#x2F;+source&#x2F;adduser&#x2F;+bug&#x2F;48734</a>
xgdgscabout 4 years ago
This could be simplified to <a href="https:&#x2F;&#x2F;bugs.launchpad.net&#x2F;ubuntu&#x2F;+source&#x2F;adduser&#x2F;+bug&#x2F;48734" rel="nofollow">https:&#x2F;&#x2F;bugs.launchpad.net&#x2F;ubuntu&#x2F;+source&#x2F;adduser&#x2F;+bug&#x2F;48734</a> is fixed.
totetsuabout 4 years ago
Even Ubuntu&#x27;s calling Linux home desktop &#x27;quaint&#x27; now..
评论 #26791990 未加载
mperhamabout 4 years ago
Tl;dr home directories now default to 750.
paxysabout 4 years ago
While the change makes sense, it&#x27;s going to be a massive headache to fix all existing software that runs as its own user when upgrading.
markstosabout 4 years ago
Too bad Red Hat is going the opposite direction with their Toolbox container management project, sharing your entire home dir with every container but not explicitly documenting this:<p><a href="https:&#x2F;&#x2F;github.com&#x2F;containers&#x2F;toolbox&#x2F;issues&#x2F;183" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;containers&#x2F;toolbox&#x2F;issues&#x2F;183</a>
alfiedotwtfabout 4 years ago
I remember a while ago, Ubuntu used encryptfs for home directories, but it was removed. Weird, because I thought it was a great idea
评论 #26787419 未加载
评论 #26790177 未加载
评论 #26790210 未加载
RcouF1uZ4gsCabout 4 years ago
Isn’t this what Windows has done by default for a while now? Every user’s home directory is private to that user.
评论 #26786671 未加载
towergratisabout 4 years ago
&gt; This change now means that in the future if an attacker were to exploit some previously unknown vulnerability in a given system service that is running as a separate user, they would then not be able to access the data of any other user (both human or system service) on the system.<p>If the attacker can already access arbitrary files on your box, I don&#x27;t think simple unix permissions will save you
评论 #26787115 未加载
评论 #26786818 未加载
intricatedetailabout 4 years ago
Ubuntu should develop shadow accounts - the user will log in to a completely different account of the same login depending on password. That is if someone forces you to log in you could use different password and pretend it is your stuff.
评论 #26787845 未加载
danieldevriesabout 4 years ago
This is already the case with systemd-homed.