Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Honest question: what security principles does this violate?


/tmp generally has more open permissions than the rest of the file system, and if you're using a known file name, you're open to that file being abused by an attacker.

I know of no good reason to not use mktemp.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: