From: Linas Vepstas <linas@austin.ibm.com>
To: linux-hotplug@vger.kernel.org
Subject: [OT] SELinux vs. other systems [was Re: [idea] udev + selinux]
Date: Tue, 31 Aug 2004 22:44:47 +0000 [thread overview]
Message-ID: <20040831224447.GA4964@austin.ibm.com> (raw)
On Tue, Aug 31, 2004 at 08:18:10PM +0100, Luke Kenneth Casson Leighton was heard to remark:
> dude, the entire selinux thing is disliked by stacks of debian
> maintainers because of the knock-on implications it has.
Totally off-topic remark, unrelated to anything, but I'm waiting
for somethig to compile :)
Every now and then, I look at SELinux, and I get scared away by its
complexity. This complexity makes it very hard to audit, and assure
oneself that its actually providing any real security, as opposed to
the illusion of security. During this email thread, there are
references to mysterious rules that neither party in the conversation
fully understands; this scares me.
Compare this to less complex security provided by e.g. the Linux
VServer project. VServer is intended to allow an ISP to pretend they
have a rack of 100 cpu's all running linux, when in fact they have just
one. The fact that it provides security is a side-effect; but its
far simpler, far easier to audit, and allows me to sleep at night.
Another example: Way back in the kernel-2.2 timeframe, I hacked on
something neat: 'LOMAC': if you came in from a network connection,
you lost permission to do almost anything, other than to e.g. webserve.
The system was simple, worked well, the kernel patches were easy to audit,
you could go home without worrying about priveledge escalation.
Compare that to this thread, where we are talking about atomic vs.
non-atomic restoration of context for udev-mounted temp file systems.
Shudder. This seems to be begging for an exploit to be discovered.
Are we sure that SELinux is really on the right track here?
--linas
-------------------------------------------------------
This SF.Net email is sponsored by BEA Weblogic Workshop
FREE Java Enterprise J2EE developer tools!
Get your free copy of BEA WebLogic Workshop 8.1 today.
http://ads.osdn.com/?ad_idP47&alloc_id\x10808&op=click
_______________________________________________
Linux-hotplug-devel mailing list http://linux-hotplug.sourceforge.net
Linux-hotplug-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/linux-hotplug-devel
next prev reply other threads:[~2004-08-31 22:44 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-08-30 17:37 [idea] udev + selinux Nigel Kukard
2004-08-30 20:31 ` Luke Kenneth Casson Leighton
2004-08-31 5:02 ` Nigel Kukard
2004-08-31 9:49 ` Luke Kenneth Casson Leighton
2004-08-31 10:27 ` Nigel Kukard
2004-08-31 12:46 ` Luke Kenneth Casson Leighton
2004-08-31 11:26 ` Luke Kenneth Casson Leighton
2004-08-31 16:07 ` Luke Kenneth Casson Leighton
2004-08-31 16:46 ` Nigel Kukard
2004-08-31 19:18 ` Luke Kenneth Casson Leighton
2004-08-31 19:26 ` Stephen Smalley
2004-08-31 20:02 ` Luke Kenneth Casson Leighton
2004-08-31 21:18 ` Jim McCullough
2004-08-31 23:26 ` Luke Kenneth Casson Leighton
2004-08-31 22:44 ` Linas Vepstas [this message]
2004-09-01 14:23 ` [OT] SELinux vs. other systems [was Re: [idea] udev + selinux] Richard Troth
2004-09-01 17:25 ` Linas Vepstas
2004-09-02 16:10 ` Stephen Smalley
2004-09-02 17:29 ` Lomac questions [was Re: [OT] SELinux vs. other systems] Linas Vepstas
2004-09-02 20:05 ` Luke Kenneth Casson Leighton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20040831224447.GA4964@austin.ibm.com \
--to=linas@austin.ibm.com \
--cc=linux-hotplug@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).