OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Here's another glibc env. var.
From: haradaobunsha.co.jp
Date: Wed May 24 2000 - 22:01:52 CDT


>(In fact, it is probably a good thing to motivate people to avoid putting
>user-friendly junk into setuid programs...)

You're removing needed functionality to get around programming errors.
Why is being able to use another language for messages from suid programs
"user-friendly junk"? I would think that it'd be better, security-wise, to
potentially give the user information in their own language, rather than
just spitting out English that they may or may not be able to read.

Bruce Harada