All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Matthew Pemble" <mpemble@isintegration.com>
To: <selinux@tycho.nsa.gov>
Subject: RE: Goal / Danger: Attack by malicious root
Date: Tue, 16 Jan 2001 09:22:45 -0000	[thread overview]
Message-ID: <004801c07f9d$e2d86780$0a02a8c0@pemble.net> (raw)
In-Reply-To: <Pine.LNX.4.21.0101151453430.18627-100000@mail.thesportsregister.com>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Consider, for a moment, the irony here. 

For the record, the "boot from your own device" solution, I agree
with, as the only way of establishing trust in your OS (although
keystroke loggers that don't use OS functions, video capture devices
etc in tampered hardware can still get you).

Take a step back - we are assuming an attacker, whether a legitimate
holder of super-user privileges whom you do not want to have access
to your data or protection against an "Evil Minded Toad" who has
stolen root.  In the former case, limiting the privileges of the root
user through MAC is good protection (assuming you can generate or
request your own MAC labels and root is not the MAC privilege
assigner.)  In the latter case, if the lab environment allows you to
boot a CD, they don't need to "hack", they can craft a malicious
version of the OS and boot that.

You, a specialist user who reads a security mailing list may be safe,
but the vast majority of users will be at greater risk than if
booting from a CD was prevented.  Who are we trying to protect?  Us
or the normal user - consider, when your boss is writing your annual
report, will (s)he take these precautions.  Mine won't.

Matthew Pemble, Principal Consultant, IS Integration,
Preston Technology Management Centre, Marsh Lane, PRESTON,
Lancashire, PR1 8UD

Tel: +44 (0)1324 820690  Fax: +44 (0)1324 826034

Head Office: 
Tel: +44 (0)1772 885850  Fax: +44 (0)1772 558881
Mobile: +44 (0)7050 128620
Mailto:mpemble@isintegration.com  Web: http://www.isintegration.com

This email and any files transmitted with it are confidential and
intended
solely for the use of the individual or entity to whom they are
addressed.
If you have received this email in error please notify your system
manager
or IS Integration Limited on +44 (0) 1772 885850

Any Views expressed in this e-mail message are those of the
individual
sending the message, except where the sender specifically states them
to be
the views of IS Integration Limited. 

-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com>

iQA/AwUBOmQOhGrvMjpl5yaUEQLQwQCgjiquMMxqV4j54RiMZF0kptVtl2sAoOQm
NmCkT9tsDvLjwn6OyNGlMAlF
=/MHf
-----END PGP SIGNATURE-----


--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2001-01-16  9:21 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-01-15 15:08 Goal / Danger: Attack by malicious root Jan Petranek
2001-01-15 13:02 ` Robert Hartley
2001-01-15 16:22 ` Bennett Todd
2001-01-15 16:52   ` Andi Kleen
2001-01-15 16:45 ` Preston L. Bannister
2001-01-15 17:53 ` Johnathon Day
2001-01-15 19:19   ` Bennett Todd
2001-01-15 21:18     ` Johnathon Day
2001-01-16  9:22       ` Matthew Pemble [this message]
2001-01-16 12:53 ` Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2001-01-16 12:28 Roger

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='004801c07f9d$e2d86780$0a02a8c0@pemble.net' \
    --to=mpemble@isintegration.com \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.