Ubuntu 21.04 will finally fix this long-time security concern

Lenovo Linux
(Image credit: Lenovo)

The next upcoming release of Ubuntu will close a security issue that’s been lingering around the popular desktop distro for more than a decade. 

The original bug report filed in lieu of this issue back in 2006 has finally been marked as fixed by Alex Murray, Ubuntu Security Tech Lead, at Canonical

Unlike many other distros, Ubuntu by default creates user home directories with world writable permissions.  Murray once again flagged the issue late last year, arguing among other things that Ubuntu now has a significant customer and user-base in the public cloud and server space for whom the world-readable home directories are “more like a footgun than a feature.”

More restrictive

It was originally argued in 2006 that world-writable directories made Ubuntu more convenient for multi-user environments, as it made sharing files between multiple users on a shared desktop much easier. 

However as Murray explained, the permissions could spell disaster in today’s connected environment.

Murray proposed changing the default settings to strip away write permissions from anyone except the owner of the directory. “By making this change now, this also gives 3 development releases and 2 interim releases to work through any unforeseen issues etc before landing in an LTS release,” explains Murray.

Since his plan didn’t receive any complaints, he has instead pushed it for implementation in the upcoming 21.04 release. With Ubuntu 21.04, newly-created users won't be world-readable but can of course be changed by the user/administrator if desired.

Via: Phoronix

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Google Pixel 8a in aloe green showing
Google Pixel 9a benchmark link teases the performance of the upcoming mid-ranger
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 17 (game #1148)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 17 (game #379)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 17 (game #645)
Apple iPhone 16 Pro HANDS ON
Leaked iPhone 17 dummy units may have given us our best look yet at all four models
A super close up image of the Google Gemini app in the Play Store
It's official: Google Assistant will be retired for phones this year, with Gemini taking over