All of lore.kernel.org
 help / color / mirror / Atom feed
* In FC8 I would like to start playing with trusted X.
@ 2007-05-15 18:44 Daniel J Walsh
  2007-05-16  0:58 ` Joshua Brindle
  2007-05-16 14:41 ` James Antill
  0 siblings, 2 replies; 10+ messages in thread
From: Daniel J Walsh @ 2007-05-15 18:44 UTC (permalink / raw)
  To: Eamon Walsh, Ted X Toth, SE Linux

Supposedly The SELinux XExtensions are in FC7 and beyond so time to 
start using them.

But lets start simple ...

Some of you are looking at using Trusted X for MLS, but I want to look 
at this from a targeted policy point of view.  What are the security 
goals of a normal Fedora user. 

Lets establish two tangible goals.

1. Only the application with focus can get keyboard input.  So if I am 
on a web page that is asking me for a password (On Line Banking) Only 
Firefox can read the input.  Not Thunderbird.
Theoretically I could run this with all apps mostly unconfined.
firefox_t can capture input on firefox_t.  While unconfined_t can not.

2. No apps except gimp can do a screen capture.  Again I want all apps 
mostly unconfined
My goal is to get  a policy that prevents any app from screen capture 
including
unconfined_t.  Bug gimp_t in the unconfined domain can.


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2007-05-18 19:53 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-05-15 18:44 In FC8 I would like to start playing with trusted X Daniel J Walsh
2007-05-16  0:58 ` Joshua Brindle
2007-05-16  1:33   ` Daniel J Walsh
2007-05-16 14:41 ` James Antill
2007-05-16 16:21   ` Daniel J Walsh
2007-05-16 16:59     ` Eamon Walsh
2007-05-16 17:07       ` Daniel J Walsh
2007-05-16 18:14         ` Eamon Walsh
2007-05-16 21:34           ` Ted X Toth
2007-05-18 19:53             ` Eamon Walsh

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.