Re: Unix domain sockets and MAC confined processes as (object) capability system?

Bill Frantz <[email protected]> Thu, 18 Feb 2016 23:19:50 -0800
Newsgroups gmane.comp.capabilities.general
Message-ID <r470Ps-10113i-FFDDBC0265AF438C8D56579876D98F6D@Williams-MacBook-Pro.local>
On 2/19/16 at 11:04 PM, rmeijer-qWit8jRvyhVmR6Xm/[email protected] (rmeijer) wrote:

>On Linux there are three interesting facilities regarding privilege separation:
>
>1) Using MAC (SELinux/AppArmor/etc) a process can be functionally cut of from access
>to most of the file-system.
>2) Using UID based firewall rules, a process running under a particular UID can be functionally
>cut of from initiating or directly accepting any network traffic.
>3) Using Unix domain sockets, open file, network connection handles and importantly other Unix
>domain sockets can be handed over between processes.

I admit that to me, Unix and friends are a black art. I was 
convinced, after a long time studying it, that Postfix did 
actually implement least privilege under Unix, so I think it can 
be done, and I take my hat off to the people who designed that system.

What worries me is what can be done with the ambient privilege 
available in Unix. If things can be fenced off well enough, I'm 
a fan, although certainly not capable of determining "well 
enough" for my self (which remains a worry).

Assuming that indeed Unix programs can be usefully contained, 
can we build a system/language/??? which makes all the mechanism 
disappear, and all we see is the capability relations? IMHO, 
that would be a very useful addition to the list of object 
capability systems.

Cheers - Bill

---------------------------------------------------------------------------
Bill Frantz        |"Web security is like medicine - trying to 
do good for
408-356-8506       |an evolved body of kludges" - Mark Miller
www.pwpconsult.com |