The murky issue of changin process identity: revising "setuid demystified"
Dan Tsafrir, Dilma Da Silva, David Wagner · ;login:: the magazine of USENIX & SAGE · 2008
Dropping unneeded process privileges promotes security but is not notoriously error-prone because of confusing set*id system calls with unclear semantics as subtle portability issues. To make things worse, existing recipes to accomoplish the task are lacking, related manuals can be misleasding, and the associated kernel subsystem might contain bugs. We therefore proclaim the systemas an untrustworthy when it comes to the subject matter, and we suggest a defensive, easy-to-use solution that adresses all concern.