Path: utzoo!attcan!utgpu!jarvis.csri.toronto.edu!rutgers!cs.utexas.edu!uunet!mcvax!kth!draken!tut!kannel!kannel.lut.fi!kim From: kim@kannel.lut.fi (Kimmo Suominen) Newsgroups: comp.emacs Subject: Re: Rmail Message-ID: Date: 3 Jul 89 16:29:07 GMT References: <416@sirius.ua.oz> <23253@news.Think.COM> Sender: news@kannel.lut.fi Organization: Lappeenranta University of Technology, Finland Lines: 48 In-reply-to: rlk@think.com's message of 30 Jun 89 13:53:48 GMT In article <23253@news.Think.COM> rlk@think.com (Robert Krawitz) writes: From: rlk@think.com (Robert Krawitz) Newsgroups: comp.emacs Keywords: Rmail Date: 30 Jun 89 13:53:48 GMT References: <416@sirius.ua.oz> Sender: news@Think.COM Reply-To: rlk@think.com (Robert Krawitz) Organization: Thinking Machines Corp., Cambridge MA Lines: 14 In article , kim@kannel (Kimmo Suominen) writes: Problem with the first solution is that anyone can now remove another person's incoming mail file. Problem with the second solution is that anyone can read someone else's mail by setting the incoming mailbox variable in Emacs (at least I think it's possible that way - I haven't tried). No, it shouldn't be possible. The individual spool files are normally set 600, so only the owner can read or write them. It doesn't prevent anyone who has access to the directory from stat'ing them, though, but movemail doesn't have any way to print out the stats coded into it. -- ames >>>>>>>>> | Robert Krawitz 245 First St. bloom-beacon > |think!rlk Cambridge, MA 02142 harvard >>>>>> . Thinking Machines Corp. (617)876-1111 Which one shouldn't be possible? (Well, yeah - it shouldn't be but it is - or did you mean "it can't be") If you have write permission to a directory, you can delete any file in it even if you don't have any rights for the file itself. If you have movemail installed as setgid to mail, then you *CAN* read another person's incoming mail. I just tried it out and it works fine (just use "set-rmail-inbox-list"). Any solutions? Kim -- ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,, ( Kimmo Suominen Electronic Mail on Internet: kim@kannel.lut.fi ) ( "That's what I think!" on Funet: KUULA::KIM ) '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''