Re: in defense of SELinux

"Karp, Alan H" <[email protected]>
Newsgroups gmane.comp.capabilities.general
Message-ID <8AD823089998C849A832D86972E69CD53E758505@G4W3222.americas.hpqcorp.net>
Rob Meijer wrote:
> 
> There is definitely value in restricting delegation in certain settings at
> certain granularity levels, so at the risk as being stoned here for
> heresy, yes mandatory access control has its place.

You can only enforce mandatory access control if you can prevent credential sharing.  Further, many MAC systems have an escape hatch for when lives are at stake. 

A better approach is Voluntary Oblivious Compliance (VOC).  With VOC, you can avoid accidental delegations that would violate policy while allowing those purposeful violations that make sense up to and including saving lives.  I've been proposing that a violation result in a dialog box saying "You are about to violate policy.  If you wish to continue, enter your justification here and click OK.  Your manager and security officer will be informed of the violation."

________________________
Alan Karp
Principal Scientist
Enterprise Services, Office of the CTO
Hewlett-Packard Company
1501 Page Mill Road
Palo Alto, CA 94304
(650) 857-3967, fax (650) 857-7029
http://www.hpl.hp.com/personal/Alan_Karp
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.