All of lore.kernel.org
 help / color / mirror / Atom feed
* SE Android and Finer Grained Permissions
@ 2012-03-05  2:02 Jeffrey Walton
  2012-03-05 15:09 ` James Carter
  2012-03-06  1:02 ` Casey Schaufler
  0 siblings, 2 replies; 8+ messages in thread
From: Jeffrey Walton @ 2012-03-05  2:02 UTC (permalink / raw)
  To: SE Linux

Hi All,

Forgive my ignorance here.....

I was reading the slides at on SE Android at
http://selinuxproject.org/~jmorris/lss2011_slides/caseforseandroid.pdf.

I see the slides point out "[Current Android suffers] limited
granularity, coarse-grained privilege." But I don't see where SE
Android corrected it. For example, it appears READ_PHONE_STATE still
encompasses reading a device serial number, IMEI, SIM ID, call state,
incoming calling number, etc.

Does SE Android remediate the coarse grained permissions?

Is an application installation still an "all or nothing" proposition
with respect to permissions? For example, can I approve an install and
later take away the WRITE_CONTACTS permission?

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2012-03-11  5:55 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2012-03-05  2:02 SE Android and Finer Grained Permissions Jeffrey Walton
2012-03-05 15:09 ` James Carter
2012-03-05 19:44   ` Stephen Smalley
2012-03-06  1:02 ` Casey Schaufler
2012-03-06  2:39   ` Jeffrey Walton
2012-03-06 15:08     ` Stephen Smalley
2012-03-06 14:53   ` Stephen Smalley
2012-03-11  5:55     ` coderman

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.