Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

The situation with default file permissions is already terrible enough that no host should ever have o+x on home directories. And once you remove that, it doesn't matter if everything inside is 777.


This doesn't work for setups with e.g. a single apache instance running as www-data.


Add the apache user to every customer's group. It can get into the files but no other users can.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: