All of lore.kernel.org
 help / color / mirror / Atom feed
* Goal / Danger: Attack by malicious root
@ 2001-01-15 15:08 Jan Petranek
  2001-01-15 13:02 ` Robert Hartley
                   ` (4 more replies)
  0 siblings, 5 replies; 11+ messages in thread
From: Jan Petranek @ 2001-01-15 15:08 UTC (permalink / raw)
  To: selinux

dear guys,

did You consider the possibility of an malicious root attacks? In most
Linuxdistributions, the priviliged user can read & manipulate all of the user's
data. 

This is indeed a situation I find myself in today: I am working on a
Linux-Machine in the university's computer pool. And I find my own
(non-encrypted) home directory far too insecure to put a private key or
something like that in here.  This is also from the point of view, that the
root-login may be hacked on a campus site like this.

So to me, there is a need of encrypting the user's data. The question of the
key yet remains: A key like a password / passphrase is quite limited in it's
length (by the memory of the user). A key on a medium (like a CD-ROM,
chipcard etc.) could be longer, but still there is the demand, that it can't be read by 
somebody else (not even the superuser), when mounted /
used by the user.
Also, the key medium could compromise the encryption, but that is another
problem.

I'd be quite glad, if you could take this point in consideration,

JanP



--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 11+ messages in thread
* Re: Goal / Danger: Attack by malicious root
@ 2001-01-16 12:28 Roger
  0 siblings, 0 replies; 11+ messages in thread
From: Roger @ 2001-01-16 12:28 UTC (permalink / raw)
  To: selinux

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> How to solve the problem? This isn't as hard as it sounds. Trying
> to stop the unstoppable is an obvious impossibility. So, instead of being
> a follower of King Canute, it makes more sense to =assume= that someone
> can/has tampered with the HW, and figure out how to limit the damage.

eh....i'd just skip the coding and go straight to using a stick of TNT and a 
'tripwire'.  



- -- 
- -----
To verify the signature, get GNUPG (Open Source PGP Security)
http://www.gnupg.org/

My pulic key (in armor format) can be found at:
http://www.alltel.net/rogerx/index.html

My ICQ UIN# = 21252173

Created with Linux Mandrake 7.2!
http://www.linux-mandrake.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.4 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iEYEARECAAYFAjpkPlYACgkQZA/JYxAFHWFreACdHIZHyNVl5ZMhnVqq3D0BmmPP
BWcAn13ARxe2NTfaheF4l2FCVa6MqSzy
=/lGL
-----END PGP SIGNATURE-----



--
You have received this message because you are subscribed to the selinux list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 11+ messages in thread

end of thread, other threads:[~2001-01-16 18:39 UTC | newest]

Thread overview: 11+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2001-01-15 15:08 Goal / Danger: Attack by malicious root Jan Petranek
2001-01-15 13:02 ` Robert Hartley
2001-01-15 16:22 ` Bennett Todd
2001-01-15 16:52   ` Andi Kleen
2001-01-15 16:45 ` Preston L. Bannister
2001-01-15 17:53 ` Johnathon Day
2001-01-15 19:19   ` Bennett Todd
2001-01-15 21:18     ` Johnathon Day
2001-01-16  9:22       ` Matthew Pemble
2001-01-16 12:53 ` Stephen Smalley
  -- strict thread matches above, loose matches on Subject: below --
2001-01-16 12:28 Roger

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.