linux-hotplug.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Linas Vepstas <linas@austin.ibm.com>
To: linux-hotplug@vger.kernel.org
Subject: [OT] SELinux vs. other systems [was Re: [idea] udev + selinux]
Date: Tue, 31 Aug 2004 22:44:47 +0000	[thread overview]
Message-ID: <20040831224447.GA4964@austin.ibm.com> (raw)

On Tue, Aug 31, 2004 at 08:18:10PM +0100, Luke Kenneth Casson Leighton was heard to remark:
>  dude, the entire selinux thing is disliked by stacks of debian
>  maintainers because of the knock-on implications it has.

Totally off-topic remark, unrelated to anything, but I'm waiting 
for somethig to compile :)  

Every now and then, I look at SELinux, and I get scared away by its
complexity.  This complexity makes it very hard to audit, and assure
oneself that its actually providing any real security, as opposed to
the illusion of security.  During this email thread, there are 
references to mysterious rules that neither party in the conversation 
fully understands; this scares me. 

Compare this to less complex security provided by e.g. the Linux 
VServer project.  VServer is intended to allow an ISP to pretend they
have a rack of 100 cpu's all running linux, when in fact they have just
one.  The fact that it provides security is a side-effect; but its 
far simpler, far easier to audit, and allows me to sleep at night.

Another example: Way back in the kernel-2.2 timeframe, I hacked on 
something neat: 'LOMAC': if you came in from a network connection, 
you lost permission to do almost anything, other than to e.g. webserve. 
The system was simple, worked well, the kernel patches were easy to audit, 
you could go home without worrying about priveledge escalation.  

Compare that to this thread, where we are talking about atomic vs.
non-atomic restoration of context for udev-mounted temp file systems.
Shudder. This seems to be begging for an exploit to be discovered.
Are we sure that SELinux is really on the right track here?

--linas


-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_idP47&alloc_id\x10808&op=click
_______________________________________________
Linux-hotplug-devel mailing list  http://linux-hotplug.sourceforge.net
Linux-hotplug-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-hotplug-devel

         reply	other threads:[~2004-08-31 22:44 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-08-30 17:37 [idea] udev + selinux Nigel Kukard
2004-08-30 20:31 ` Luke Kenneth Casson Leighton
2004-08-31  5:02   ` Nigel Kukard
2004-08-31  9:49     ` Luke Kenneth Casson Leighton
2004-08-31 10:27       ` Nigel Kukard
2004-08-31 12:46         ` Luke Kenneth Casson Leighton
2004-08-31 11:26       ` Luke Kenneth Casson Leighton
2004-08-31 16:07 ` Luke Kenneth Casson Leighton
2004-08-31 16:46   ` Nigel Kukard
2004-08-31 19:18     ` Luke Kenneth Casson Leighton
2004-08-31 19:26       ` Stephen Smalley
2004-08-31 20:02         ` Luke Kenneth Casson Leighton
2004-08-31 21:18           ` Jim McCullough
2004-08-31 23:26             ` Luke Kenneth Casson Leighton
2004-08-31 22:44       ` Linas Vepstas [this message]
2004-09-01 14:23         ` [OT] SELinux vs. other systems [was Re: [idea] udev + selinux] Richard Troth
2004-09-01 17:25         ` Linas Vepstas
2004-09-02 16:10           ` Stephen Smalley
2004-09-02 17:29             ` Lomac questions [was Re: [OT] SELinux vs. other systems] Linas Vepstas
2004-09-02 20:05               ` Luke Kenneth Casson Leighton

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040831224447.GA4964@austin.ibm.com \
    --to=linas@austin.ibm.com \
    --cc=linux-hotplug@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).