Re: Unix domain sockets and MAC confined processes as (object) capability system?
Bill Frantz <[email protected]> Thu, 18 Feb 2016 23:19:50 -0800
| Newsgroups | gmane.comp.capabilities.general |
|---|---|
| Message-ID | <r470Ps-10113i-FFDDBC0265AF438C8D56579876D98F6D@Williams-MacBook-Pro.local> |
On 2/19/16 at 11:04 PM, rmeijer-qWit8jRvyhVmR6Xm/[email protected] (rmeijer) wrote: >On Linux there are three interesting facilities regarding privilege separation: > >1) Using MAC (SELinux/AppArmor/etc) a process can be functionally cut of from access >to most of the file-system. >2) Using UID based firewall rules, a process running under a particular UID can be functionally >cut of from initiating or directly accepting any network traffic. >3) Using Unix domain sockets, open file, network connection handles and importantly other Unix >domain sockets can be handed over between processes. I admit that to me, Unix and friends are a black art. I was convinced, after a long time studying it, that Postfix did actually implement least privilege under Unix, so I think it can be done, and I take my hat off to the people who designed that system. What worries me is what can be done with the ambient privilege available in Unix. If things can be fenced off well enough, I'm a fan, although certainly not capable of determining "well enough" for my self (which remains a worry). Assuming that indeed Unix programs can be usefully contained, can we build a system/language/??? which makes all the mechanism disappear, and all we see is the capability relations? IMHO, that would be a very useful addition to the list of object capability systems. Cheers - Bill --------------------------------------------------------------------------- Bill Frantz |"Web security is like medicine - trying to do good for 408-356-8506 |an evolved body of kludges" - Mark Miller www.pwpconsult.com |