All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Joshua Brindle" <JBrindle@snu.edu>
To: <kayo@pyra.ca>, <bam@snoopy.apana.org.au>
Cc: <SELinux@tycho.nsa.gov>
Subject: Re: user transparent encryption
Date: Sun, 16 Feb 2003 23:40:01 -0600	[thread overview]
Message-ID: <se502174.064@atlas.snu.edu> (raw)

I've pondered this myself, suppose you have a great selinux setup
very secure, no easy way to compromise it, but the machine itself
was in a hostile environment (not able to be protected from others
well). What is to stop someone from booting up a non-selinux kernel
and having at it with your filesystems? Nothing. I've often wondered
if there is a way to lock down the drive contents so it is not
accessible 
(at least easily) by a non-selinux kernel, or even the encrypted fs
where the key is compiled securely into a selinux-enabled kernel
so that with a new (possible non-selinux) kernel the filesystem would
not be readable. Do you guys think this is possible? granted it would
make system recovery next to impossible but maybe it would be a 
good option for folks with malicious or ignorant users/-co admins?

Joshua Brindle
UNIX Administrator
Southern Nazarene University

>>> Brian May <bam@snoopy.apana.org.au> 02/16/03 08:43PM >>>
On Sun, Feb 16, 2003 at 08:18:16PM -0600, kayo wrote:
> I am wondering if any of you have heard of a file system encryption
> service that is or close to transparent to users in which couldnt be
> easily compramised even if root was. Or have any ideas on how this
could
> be done. I know using a loopback type scheam that once mounted or
while
> mounting root could steal the key or the data that should be
private.
> Has any one heard of a group that are brainstorming simular
concepts?

What type of attack are you trying to protect your data from?

If you don't trust the adminstrator, there is nothing you can do, root
needs to access the entire system for adminstration. He/she can
commands
like run "su userid" for instance to become your UID. Even SE-Linux
policy won't help, and presumably it is the adminstrator who sets the
policy.

If on the otherhand, you are more concerned about a program running
as root which could be compromised and allow access to private files,
SE-Linux can help by limiting the prvileges that these programs have.
-- 
Brian May <bam@snoopy.apana.org.au>

--
This message was distributed to subscribers of the selinux mailing
list.
If you no longer wish to subscribe, send mail to
majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

             reply	other threads:[~2003-02-17  5:40 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-02-17  5:40 Joshua Brindle [this message]
2003-02-17  7:43 ` user transparent encryption Thomas Walcott
2003-02-17  9:18 ` Russell Coker
2003-02-17 15:28   ` w9ya
2003-02-17 15:20 ` Dale Amon
  -- strict thread matches above, loose matches on Subject: below --
2003-02-17  2:18 kayo
2003-02-17  2:43 ` Brian May
2003-02-17  5:43 ` kayo
2003-02-17  8:47   ` Carsten Grohmann
2003-02-17 11:54   ` Tom

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=se502174.064@atlas.snu.edu \
    --to=jbrindle@snu.edu \
    --cc=SELinux@tycho.nsa.gov \
    --cc=bam@snoopy.apana.org.au \
    --cc=kayo@pyra.ca \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.