All of lore.kernel.org
 help / color / mirror / Atom feed
From: guido@trentalancia.com (Guido Trentalancia)
To: refpolicy@oss.tresys.com
Subject: [refpolicy] Question: and the policy grows...
Date: Fri, 18 Mar 2011 16:09:17 +0100	[thread overview]
Message-ID: <1300460957.4019.16.camel@tesla.lan> (raw)
In-Reply-To: <4D8361F7.8060007@tresys.com>

Hello Christopher !

On Fri, 18/03/2011 at 09.45 -0400, Christopher J. PeBenito wrote:
> On 03/17/11 15:40, Guido Trentalancia wrote:
> > On Thu, 17/03/2011 at 12.44 -0400, Daniel J Walsh wrote:
> >> On 03/17/2011 12:04 PM, Guido Trentalancia wrote:
> >>> On Thu, 17/03/2011 at 10.25 -0400, Daniel J Walsh wrote:
> 
> >> I think getting people to go in and examine the policy and ask
> >> questions, why do we have these rules would be helpful.  Maybe we setup
> >> test days, or something to remove bogus policy.
> > 
> > There is at least the limit of not having many people on this list
> > compared to most other Linux projects. Perhaps security is considered
> > something boring to the average user/developer. Or even more likely
> > SELinux is still perceived as "difficult to get into" (a documentation
> > issue).
> 
> I think theres two things.
> 
> 1. People don't actually care about security, especially if it
> complicates/hinders what they're trying to do.  Most people seek
> security measures as a reaction to a security breach.

Typically at that point it would be too late (as opposed to the example
of medicine/health where usually something could still be done).

The second most common reason I have been given (apart from "it will
never happen to me") is in fact: "I am afraid the system would stop
working". At least there is some rationale behind this second reason...

> 2. Of the people that have some interest, SELinux is typically seen as
> too difficult.  We've been working on improving this for years.

I think Dominick reply got straight to the point (which applies in
general to MAC strategy not just SELinux):

"SELinux is not so hard in my view considering its flexibility. But
Linux is complex and vast." (Fri, 18 Mar 2011 11:12:43 +0100)

Many people just want to have a piece of software called "anti-virus"
enclosed in beautiful and colored package backed by lots of
advertisement on the public media and such piece of software should tell
them that things are all right most of the time or otherwise that issues
are getting tackled within seconds and that everything will get back to
normality within the same amount of time.

But why are we not moving this discussion to the proper thread started
by Russel on the SELinux mailing list ? My original question had nothing
to do with this, as it was about policy management.

There we could discuss and plan how to improve the documentation
further.

Regards,

Guido

  reply	other threads:[~2011-03-18 15:09 UTC|newest]

Thread overview: 46+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-03-17 13:50 [refpolicy] Question: and the policy grows Guido Trentalancia
2011-03-17 14:25 ` Daniel J Walsh
2011-03-17 16:04   ` Guido Trentalancia
2011-03-17 16:44     ` Daniel J Walsh
2011-03-17 17:54       ` Christopher J. PeBenito
2011-03-17 18:34         ` Daniel J Walsh
2011-03-17 19:49           ` Daniel J Walsh
2011-03-18 13:30           ` Christopher J. PeBenito
2011-03-17 20:15         ` Guido Trentalancia
2011-03-18 13:35           ` Christopher J. PeBenito
2011-03-18 15:25             ` Guido Trentalancia
2011-03-17 19:40       ` Guido Trentalancia
2011-03-17 19:55         ` Daniel J Walsh
2011-03-17 20:27           ` Guido Trentalancia
2011-03-18 13:38             ` Christopher J. PeBenito
2011-03-17 20:24         ` Sven Vermeulen
2011-03-17 21:08           ` Guido Trentalancia
2011-03-17 21:34             ` Sven Vermeulen
2011-03-17 23:04               ` Guido Trentalancia
2011-03-18 13:52               ` Christopher J. PeBenito
2011-03-18 15:20                 ` Guido Trentalancia
2011-03-17 23:08           ` Mark Montague
2011-03-18  6:06             ` Sven Vermeulen
2011-03-18 10:19               ` Dominick Grift
2011-03-18 12:31               ` Guido Trentalancia
2011-03-17 22:56         ` Mark Montague
2011-03-18 10:12           ` Dominick Grift
2011-03-18 13:37           ` Stephen Smalley
2011-03-18 15:37           ` Dominick Grift
2011-03-17 23:24         ` SE Linux use - was: " Russell Coker
2011-03-18  0:33           ` Guido Trentalancia
2011-03-18  2:11           ` Jason Axelson
2011-03-18 13:23           ` James Carter
2011-03-18 14:33             ` Russell Coker
2011-03-18 14:57               ` Christopher J. PeBenito
2011-03-18 15:48                 ` Guido Trentalancia
2011-03-18 23:40                 ` Russell Coker
2011-03-18 15:45               ` Guido Trentalancia
2011-03-18 23:52                 ` Russell Coker
2011-03-19 14:37                   ` Guido Trentalancia
2011-03-18 14:08           ` Christopher J. PeBenito
2011-03-18 13:45         ` [refpolicy] " Christopher J. PeBenito
2011-03-18 15:09           ` Guido Trentalancia [this message]
2011-03-18 17:14           ` [refpolicy] dual mailing list (was Question: and the policy grows...) Guido Trentalancia
2011-03-18 18:40             ` Daniel J Walsh
2011-03-18 19:13               ` Guido Trentalancia

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1300460957.4019.16.camel@tesla.lan \
    --to=guido@trentalancia.com \
    --cc=refpolicy@oss.tresys.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.