1 |
On 2017-01-28 22:40, Alan McKinnon wrote: |
2 |
|
3 |
> There are valid cases where denying read access to crontabs is |
4 |
> desirable, for example a command run from cron requires a password and |
5 |
> the only way to provide it is on the command line. Such programs |
6 |
> exist, and the cron app provides a way to limit exposure. |
7 |
|
8 |
I have to disagree. By this argument, /sbin and /usr/sbin shouldn't be |
9 |
readable either. |
10 |
|
11 |
The password can be in a file, and read into a shell variable. |
12 |
|
13 |
Apart from that, there's also Frank's objection. Maybe /proc/cmdline |
14 |
can be disabled, though. In that case ps wouldn't be able to see the |
15 |
arguments. |
16 |
|
17 |
-- |
18 |
Please *no* private Cc: on mailing lists and newsgroups |
19 |
Personal signed mail: please _encrypt_ and sign |
20 |
Don't clear-text sign: http://cr.yp.to/smtp/8bitmime.html |