Re: Slides
"Jonathan S. Shapiro" <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CAAP=3QOQrO890rEz8Rpy3f7kfzaVgJ4012k=VfCZgM48p0S4Og@mail.gmail.com> |
I also get a 404, and I'd like to look at the slides. On Sun, Aug 4, 2013 at 11:13 AM, Guido Witmond <guido-EBfTt96odT/[email protected]> wrote: > I don't know about the other 49, I found your talk useful. You gave me a > good overview of what's wrong with AppArmor and where and how to use > MinorFS.... Since I can't see the slides, I can't comment, but I think it's important to recognize that AppArrmor isn't intended as any sort of "silver bullet". AppArmor should probably be seen as a reaction to SELinux, which is far too complicated to be useful in practice. I actually *do* know how SELinux works, and I've build SELinux profiles (or whatever the hell they are called), and it's *awful*. For most people, you can forget it. That's why most people run with SELinux disabled on systems that support it. AppArmor, whatever its flaws, has a policy specification language that administrators can actually get their heads around, and is universally viewed as easier to administer. It's also generally recognized as less powerful than SELinux, mainly because SELinux is operates at finer granularity. I've never seen anybody give a compelling use case where that finer granularity was pragmatically useful. Crispin Cowan (AppArmor's architect) is not the world's most intrepid theoretical computer security guy, and he doesn't claim to be. In my opinion, he's far and away one of the best at choosing and realizing an effective balance point between hypothetically achievable security and real-world usability. Though the folks on this list are more aware than most, I think that this kind of "real world realization" skill tends to be woefully underappreciated by computer scientists at large. When you go out and search the web, you find that the people debating AppArmor and SELinux invariably compare and contrast the *hypothetical* capabilities of these systems rather than the capabilities that are deployable by real-world users. Having worked with both, My opinion is that AppArmor wins, because the likelihood that it is actually *used* - and even used effectively, within its limits - is far higher than SELinux. And for a more subtle reason as well. AppArmor can be *explained* to a normal mortal where SELinux can't be. And if you know what something *does*, then of course it's possible to have a handle on what it *doesn't* do - which is very important if you're in the business of playing defender. Can it be improved? Certainly. And I look forward to seeing Rob's suggestions about that. I guess what I'm trying to say is that we always need to keep our sights on usability when we talk about security solutions. I imagine Rob has likely done that, and I look forward to a chance to see his slides. shap _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk