Re: Fedora/RedHat is moving is a similar direction

Sergio Tortosa Benedito <[email protected]>
Newsgroups gmane.linux.distributions.gobo.general
Message-ID <CAPiRi8MSG3YMx0=q2Y+f0QBkZ6qpc1PTTLyt_LrsGumgVnTyrg@mail.gmail.com>
El 5/9/2015 6:56 p. m., "Trans" <[email protected]> escribió:
>
> On Sat, Sep 5, 2015 at 12:28 PM, Sergio Tortosa Benedito
> <[email protected]> wrote:
>
> >> You should be able to do that with Docker.
> > Let's take the most lightweight way of having another OS inside an
already
> > existing one: chroot, even with that the system might have to load a
lot of
> > stuff (libraries, config, resources...) , however much of these stuff
might
> > already be inside the host and thus duplicating them.
>
> That's true, but maybe some duplication also contributes to security?

I doubt it, the only benefit from duplication I could see would be in
configuration, in case of corrupted/hacked binaries and because we might
have diferent versions and thus *potentially* different bugs, but none of
this would be considered as a true security feature.
> >> > All within 1 user account, so that this can be done for multiple
> >> > users, side-by-side, even concurrently on a multiuser host.
> >> >
> >> > It is nothing to do with user accounts; these are irrelevant to it.
> >>
> >> But isolating users to there own contained OS on a multi-user system
> >> would nonetheless be a step in the right direction, wouldn't it?
> > Well, remember we are unix (sort-of) and as far as I remember, unix
already
> > does this, right?
> > Even for those parts where unix itself is not enough, we already have
> > policies(SELinux), which I think are more flexible anyway.
>
> Hmm.. then why is that not good enough for applications too?

Those are different level, one thing is to isolate users so that their bad
impact on a system is minimum, so we want to isolate apps so that their
impact on the user (and thus on the system is minimum).

>I know on
> my Debian system Apache runs as www-data user, for instance.

Oops, you got me there, but I guess is a way to maintain things clean...

> > Don't worry, the lock on the front door is there :).
>
> :-)
> _______________________________________________
> gobolinux-users mailing list
> [email protected]
> http://lists.gobolinux.org/mailman/listinfo/gobolinux-users

_______________________________________________
gobolinux-users mailing list
[email protected]
http://lists.gobolinux.org/mailman/listinfo/gobolinux-users
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.