Re: Slides

"Jonathan S. Shapiro" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAAP=3QOQrO890rEz8Rpy3f7kfzaVgJ4012k=VfCZgM48p0S4Og@mail.gmail.com>
I also get a 404, and I'd like to look at the slides.

On Sun, Aug 4, 2013 at 11:13 AM, Guido Witmond <guido-EBfTt96odT/[email protected]> wrote:

> I don't know about the other 49, I found your talk useful. You gave me a
> good overview of what's wrong with AppArmor and where and how to use
> MinorFS....


Since I can't see the slides, I can't comment, but I think it's important
to recognize that AppArrmor isn't intended as any sort of "silver bullet".

AppArmor should probably be seen as a reaction to SELinux, which is far too
complicated to be useful in practice. I actually *do* know how SELinux
works, and I've build SELinux profiles (or whatever the hell they are
called), and it's *awful*. For most people, you can forget it. That's why
most people run with SELinux disabled on systems that support it.

AppArmor, whatever its flaws, has a policy specification language that
administrators can actually get their heads around, and is universally
viewed as easier to administer. It's also generally recognized as less
powerful than SELinux, mainly because SELinux is operates at finer
granularity. I've never seen anybody give a compelling use case where that
finer granularity was pragmatically useful.

Crispin Cowan (AppArmor's architect) is not the world's most intrepid
theoretical computer security guy, and he doesn't claim to be. In my
opinion, he's far and away one of the best at choosing and realizing an
effective balance point between hypothetically achievable security and
real-world usability. Though the folks on this list are more aware than
most, I think that this kind of "real world realization" skill tends to be
woefully underappreciated by computer scientists at large.

When you go out and search the web, you find that the people debating
AppArmor and SELinux invariably compare and contrast the
*hypothetical* capabilities
of these systems rather than the capabilities that are deployable by
real-world users. Having worked with both, My opinion is that AppArmor
wins, because the likelihood that it is actually *used* - and even used
effectively, within its limits - is far higher than SELinux. And for a more
subtle reason as well. AppArmor can be *explained* to a normal mortal where
SELinux can't be. And if you know what something *does*, then of course
it's possible to have a handle on what it *doesn't* do - which is very
important if you're in the business of playing defender.

Can it be improved? Certainly. And I look forward to seeing Rob's
suggestions about that.

I guess what I'm trying to say is that we always need to keep our sights on
usability when we talk about security solutions. I imagine Rob has likely
done that, and I look forward to a chance to see his slides.


shap

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.