in defense of SELinux

David Nicol <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <CAFwScO9ijFZf=Cd0_iK40cX_AHSuHwyzf3RuAKy9RVSqXh+SjQ@mail.gmail.com>
On Thu, Oct 10, 2013 at 2:09 AM, Jed Donnelley <capability-iCFHVraI1K1Wk0Htik3J/[email protected]>wrote:
>
> ---  Just a mild style comment on the talk:  Dr. Watson seems very
> deferential in his discussion of comparisons with MAC mechanisms - such
> as SELinux.  I have to admit that I have an automatic gag reflex
> whenever I write or speak the word SELinux, but I think that even
> objectively Dr. Watson didn't make clear just how problematic the global
> policy mechanisms of something like SELinux are.  It's like trying to be
> God or a Communist government developing a 10 year plan and tracking,
> via explicit policy, everything that goes on in a computer system (not
> to mention network).  Things change too quickly.  It simply can't be
> done.   With capabilities (access control objects) you allow the
> programmers to manipulate access control where it makes sense through
> the communication channels between what he refers to as "sandboxes" (in
> other contexts processes or domains).  I believe this distinction is
> significantly more than religion.
>

SELinux is appropriate for locking down production systems, and for that
purpose it works as designed.


-- 

The one L lama, he's a priest
The two L llama, he's a beast
And I will bet my silk pyjama
There isn't any three L lllama. -- Ogden Nash

_______________________________________________
cap-talk mailing list
[email protected]
http://www.eros-os.org/mailman/listinfo/cap-talk
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.