logoalt Hacker News

freeone3000 • yesterday at 4:47 PM • 2 replies • view on HN

Windows already has a multi-user security context, with file- and API-level permissioning. We often call it “Users” or “RBAC”. I’ve read it and I’m still not sure what I can do now that I couldn’t a week ago.


Replies

eddythompson80 • yesterday at 6:45 PM

The same-machine-multi-user security paradigm has been dead for a long time. Even on linux, you pretty much assume root or non-root and leave it at that. You then use other layers (namespacing, kvm, etc) to enforce actual security isolation and controls.

root/non-root split is almost entirely used as a "don't let people accidentally shoot themselves in the foot" mechanism these days. Like you don't want your point-of-sale operator to accidentally disable the network or mess up the firewall rules effectively bricking the machine. Requiring an IT person to make the trip to fix it for them. But you would never "trust" the separate user profile on that POS machine as something keeping a purposefully malicious employee out of a secure system. The entire machine, regardless of the user profile, is the same security context. The uid/gid concept is an antique from the 80s that stopped working a long time ago. It's just an organizational primitive now for the most part.

I remember the fun days of the 90s and early 2000s when there were shared machines that a ton of people would ssh or rdp into with different user account and "share compute". It was fun, but absolutely no bueno for a long time now.

➕ show 1 reply
MrBuddyCasino • yesterday at 6:26 PM

Can you restrict accessible IP ranges by user?

➕ show 1 reply