back

by zorked·13y ago·view on hn ↗
Actually, even in the classical Unix security model, setuid'ing to nobody is considered a bad idea. Because so many services do it, giving an attacker an opportunity to become nobody will likely grant him access to those other services as well.
1 comments
Point taken. Allow me to revise my statement.

"In production, one should create a specialized user to run any service." And if you have lots of money to waste, stick 'em all in separate VMs too.