Everyone has read access to user's home directories by default

Bug #460490 reported by CalderCoalson
This bug report is a duplicate of:  Bug #48734: Home permissions too open. Edit Remove
16
This bug affects 3 people
Affects Status Importance Assigned to Milestone
One Hundred Papercuts
New
Undecided
Unassigned

Bug Description

Mac OS X takes the proper approach of giving each user a "Public" folder that is read-only to everyone, and restricting access to all other folders. As it stands in Ubuntu, documents, pictures, movies, even saved passwords, etc... are accessible to everyone with an account on the same computer. Security by default and vulnerability by choice is a much better approach.

Revision history for this message
Matthew Paul Thomas (mpt) wrote :

The current behavior is a deliberate and publicly-known design choice, so this bug report does not need to be private.

I agree with you that it is a poor design choice, and private-by-default would be better.

Discussions elsewhere:
http://ubuntuforums.org/showthread.php?t=1210175
http://brainstorm.ubuntu.com/idea/6106/
https://wiki.ubuntu.com/SecureHome
https://blueprints.launchpad.net/ubuntu/+spec/secure-home

visibility: private → public
Revision history for this message
CalderCoalson (ccoal) wrote : Re: [Bug 460490] Re: Everyone has read access to user's home directories by default

Sorry, didn't mean to make it private...

2009/10/26 Matthew Paul Thomas <email address hidden>

> The current behavior is a deliberate and publicly-known design choice,
> so this bug report does not need to be private.
>
> I agree with you that it is a poor design choice, and private-by-default
> would be better.
>
> Discussions elsewhere:
> http://ubuntuforums.org/showthread.php?t=1210175
> http://brainstorm.ubuntu.com/idea/6106/
> https://wiki.ubuntu.com/SecureHome
> https://blueprints.launchpad.net/ubuntu/+spec/secure-home
>
> ** Visibility changed to: Public
>
> --
> Everyone has read access to user's home directories by default
> https://bugs.launchpad.net/bugs/460490
> You received this bug notification because you are a direct subscriber
> of the bug.
>
> Status in One Hundred Paper Cuts: New
>
> Bug description:
> Mac OS X takes the proper approach of giving each user a "Public" folder
> that is read-only to everyone, and restricting access to all other folders.
> As it stands in Ubuntu, documents, pictures, movies, even saved passwords,
> etc... are accessible to everyone with an account on the same computer.
> Security by default and vulnerability by choice is a much better approach.
>

Revision history for this message
CalderCoalson (ccoal) wrote :

It seems like there is something of a consensus behind this. So why hasn't
it been changed to date?

2009/10/26 Calder Coalson <email address hidden>

> Sorry, didn't mean to make it private...
>
> 2009/10/26 Matthew Paul Thomas <email address hidden>
>
>> The current behavior is a deliberate and publicly-known design choice,
>> so this bug report does not need to be private.
>>
>> I agree with you that it is a poor design choice, and private-by-default
>> would be better.
>>
>> Discussions elsewhere:
>> http://ubuntuforums.org/showthread.php?t=1210175
>> http://brainstorm.ubuntu.com/idea/6106/
>> https://wiki.ubuntu.com/SecureHome
>> https://blueprints.launchpad.net/ubuntu/+spec/secure-home
>>
>> ** Visibility changed to: Public
>>
>> --
>> Everyone has read access to user's home directories by default
>> https://bugs.launchpad.net/bugs/460490
>> You received this bug notification because you are a direct subscriber
>> of the bug.
>>
>> Status in One Hundred Paper Cuts: New
>>
>> Bug description:
>> Mac OS X takes the proper approach of giving each user a "Public" folder
>> that is read-only to everyone, and restricting access to all other folders.
>> As it stands in Ubuntu, documents, pictures, movies, even saved passwords,
>> etc... are accessible to everyone with an account on the same computer.
>> Security by default and vulnerability by choice is a much better approach.
>>
>
>

Revision history for this message
Matthew Paul Thomas (mpt) wrote :

There is no consensus that I'm aware of. Anyone can post a forum thread or make a wiki page.

Revision history for this message
Rykel from Singapore (rykel98) wrote :

I want to add my vote to Security on this issue... it is terrible to know that other users can read my home folder!

Luke Faraone (lfaraone)
security vulnerability: yes → no
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.