Re: Fedora/RedHat is moving is a similar direction
Sergio Tortosa Benedito <[email protected]>
| Newsgroups | gmane.linux.distributions.gobo.general |
|---|---|
| Message-ID | <CAPiRi8MSG3YMx0=q2Y+f0QBkZ6qpc1PTTLyt_LrsGumgVnTyrg@mail.gmail.com> |
El 5/9/2015 6:56 p. m., "Trans" <[email protected]> escribió: > > On Sat, Sep 5, 2015 at 12:28 PM, Sergio Tortosa Benedito > <[email protected]> wrote: > > >> You should be able to do that with Docker. > > Let's take the most lightweight way of having another OS inside an already > > existing one: chroot, even with that the system might have to load a lot of > > stuff (libraries, config, resources...) , however much of these stuff might > > already be inside the host and thus duplicating them. > > That's true, but maybe some duplication also contributes to security? I doubt it, the only benefit from duplication I could see would be in configuration, in case of corrupted/hacked binaries and because we might have diferent versions and thus *potentially* different bugs, but none of this would be considered as a true security feature. > >> > All within 1 user account, so that this can be done for multiple > >> > users, side-by-side, even concurrently on a multiuser host. > >> > > >> > It is nothing to do with user accounts; these are irrelevant to it. > >> > >> But isolating users to there own contained OS on a multi-user system > >> would nonetheless be a step in the right direction, wouldn't it? > > Well, remember we are unix (sort-of) and as far as I remember, unix already > > does this, right? > > Even for those parts where unix itself is not enough, we already have > > policies(SELinux), which I think are more flexible anyway. > > Hmm.. then why is that not good enough for applications too? Those are different level, one thing is to isolate users so that their bad impact on a system is minimum, so we want to isolate apps so that their impact on the user (and thus on the system is minimum). >I know on > my Debian system Apache runs as www-data user, for instance. Oops, you got me there, but I guess is a way to maintain things clean... > > Don't worry, the lock on the front door is there :). > > :-) > _______________________________________________ > gobolinux-users mailing list > [email protected] > http://lists.gobolinux.org/mailman/listinfo/gobolinux-users _______________________________________________ gobolinux-users mailing list [email protected] http://lists.gobolinux.org/mailman/listinfo/gobolinux-users