All of lore.kernel.org
 help / color / mirror / Atom feed
From: Daniel J Walsh <dwalsh@redhat.com>
To: Joshua Brindle <method@manicmethod.com>
Cc: Eamon Walsh <ewalsh@tycho.nsa.gov>, Ted X Toth <txtoth@gmail.com>,
	SE Linux <selinux@tycho.nsa.gov>
Subject: Re: In FC8 I would like to start playing with trusted X.
Date: Tue, 15 May 2007 21:33:44 -0400	[thread overview]
Message-ID: <464A5F78.7070607@redhat.com> (raw)
In-Reply-To: <464A5732.2080603@manicmethod.com>

Joshua Brindle wrote:
> Daniel J Walsh wrote:
>> Supposedly The SELinux XExtensions are in FC7 and beyond so time to 
>> start using them.
>>
>> But lets start simple ...
>>
>> Some of you are looking at using Trusted X for MLS, but I want to 
>> look at this from a targeted policy point of view.  What are the 
>> security goals of a normal Fedora user.
>> Lets establish two tangible goals.
>>
>> 1. Only the application with focus can get keyboard input.  So if I 
>> am on a web page that is asking me for a password (On Line Banking) 
>> Only Firefox can read the input.  Not Thunderbird.
>> Theoretically I could run this with all apps mostly unconfined.
>> firefox_t can capture input on firefox_t.  While unconfined_t can not.
>>
>
> how many apps are you planning on confining for this goal? There are 
> very important ones (like gnome-agent) and less important ones 
> (firefox passwords that are stored on disk can be read by unconfined 
> anyway)
I am looking to experiment.  Right now we supposedly have technology 
that no one is using.  If I can prevent the case of entering my password 
for my online banking from any other app capturing keyboard input.  I 
will sleep slightly better.  I don't tell Firefox to recode this password.

gnome-agent would be another.   I would like to be able to disallow all 
apps from capturing keyboard input without having focus, if possible. 
>
>> 2. No apps except gimp can do a screen capture.  Again I want all 
>> apps mostly unconfined
>> My goal is to get  a policy that prevents any app from screen capture 
>> including
>> unconfined_t.  Bug gimp_t in the unconfined domain can.
>>
>
> I think you might run into some resistance here, there are dozens of 
> programs that do screen captures (screensavers, any of the many screen 
> capture programs, vnc server, etc)
>
> And I bet (though I'm not sure) that an unconfined program could run 
> gimp with the right command options to take a screen capture and save 
> it to a file that would be accessible by said program.
Yes, but at least we could begin to isolate these apps into 
unconfined_screencapture apps, and then certification people could start 
to eliminate these apps from being installed.

In order to get Trusted X to work for the Black opps people, we have to 
get it working for the targeted policy.  Whether it is a small fence or 
a large fence... 

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  reply	other threads:[~2007-05-16  1:33 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-05-15 18:44 In FC8 I would like to start playing with trusted X Daniel J Walsh
2007-05-16  0:58 ` Joshua Brindle
2007-05-16  1:33   ` Daniel J Walsh [this message]
2007-05-16 14:41 ` James Antill
2007-05-16 16:21   ` Daniel J Walsh
2007-05-16 16:59     ` Eamon Walsh
2007-05-16 17:07       ` Daniel J Walsh
2007-05-16 18:14         ` Eamon Walsh
2007-05-16 21:34           ` Ted X Toth
2007-05-18 19:53             ` Eamon Walsh

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=464A5F78.7070607@redhat.com \
    --to=dwalsh@redhat.com \
    --cc=ewalsh@tycho.nsa.gov \
    --cc=method@manicmethod.com \
    --cc=selinux@tycho.nsa.gov \
    --cc=txtoth@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.