Re: creating backups in temporary directories

From: Richard Stallman
Subject: Re: creating backups in temporary directories
Date: Sat, 08 Sep 2007 15:47:36 -0400

    IIUC this depends on backup-by-copying.  If backup-by-copying is nil, then
    the problem is indeed not present, but you get another one insted: right
    after Emacs moves /tmp/foo to /tmp/foo~ another user can add a symlink
    /tmp/foo that points to an interesting place and then when Emacs
    subsequently writes the new /tmp/foo it gets written to the location chosen
    by the attacker.

I think we can't do anything to get rid of that problem.
Writing thru symlinks is an important feature; if other people
can create the symlink, it follows inevitably that they could do this.

