Re: Slides
Ben Laurie <[email protected]>
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <CABrd9SSUJrDqrOmnofX=ATWqyTXEKHkuRo9LNK78Vy3Z3k0WeA@mail.gmail.com> |
On 4 August 2013 21:53, Jonathan S. Shapiro <[email protected]> wrote: > I also get a 404, and I'd like to look at the slides. > > On Sun, Aug 4, 2013 at 11:13 AM, Guido Witmond <guido-EBfTt96odT/[email protected]> wrote: > >> I don't know about the other 49, I found your talk useful. You gave me a >> good overview of what's wrong with AppArmor and where and how to use >> MinorFS.... > > > Since I can't see the slides, I can't comment, but I think it's important > to recognize that AppArrmor isn't intended as any sort of "silver bullet". > > AppArmor should probably be seen as a reaction to SELinux, which is far > too complicated to be useful in practice. I actually *do* know how > SELinux works, and I've build SELinux profiles (or whatever the hell they > are called), and it's *awful*. For most people, you can forget it. That's > why most people run with SELinux disabled on systems that support it. > I thought AppArmor was built in parallel to SELinux, so not really a reaction? > AppArmor, whatever its flaws, has a policy specification language that > administrators can actually get their heads around, and is universally > viewed as easier to administer. It's also generally recognized as less > powerful than SELinux, mainly because SELinux is operates at finer > granularity. I've never seen anybody give a compelling use case where that > finer granularity was pragmatically useful. > > Crispin Cowan (AppArmor's architect) is not the world's most intrepid > theoretical computer security guy, and he doesn't claim to be. In my > opinion, he's far and away one of the best at choosing and realizing an > effective balance point between hypothetically achievable security and > real-world usability. Though the folks on this list are more aware than > most, I think that this kind of "real world realization" skill tends to be > woefully underappreciated by computer scientists at large. > > When you go out and search the web, you find that the people debating > AppArmor and SELinux invariably compare and contrast the *hypothetical* capabilities > of these systems rather than the capabilities that are deployable by > real-world users. Having worked with both, My opinion is that AppArmor > wins, because the likelihood that it is actually *used* - and even used > effectively, within its limits - is far higher than SELinux. And for a more > subtle reason as well. AppArmor can be *explained* to a normal mortal > where SELinux can't be. And if you know what something *does*, then of > course it's possible to have a handle on what it *doesn't* do - which is > very important if you're in the business of playing defender. > > Can it be improved? Certainly. And I look forward to seeing Rob's > suggestions about that. > > I guess what I'm trying to say is that we always need to keep our sights > on usability when we talk about security solutions. I imagine Rob has > likely done that, and I look forward to a chance to see his slides. > > > shap > > > _______________________________________________ > cap-talk mailing list > [email protected] > http://www.eros-os.org/mailman/listinfo/cap-talk > > _______________________________________________ cap-talk mailing list [email protected] http://www.eros-os.org/mailman/listinfo/cap-talk