Re: Secure Linux From Scratch
Christos Gioran <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
> > I think we should begin at least a draft. Will start working on one > > really soon...maybe tomorrow. Let's start pouring ideas in. > > This is what I have so far, it's pretty cheesy. > > Code Authoring > All code, either in binary or source form, introduced to the system must > come from a responcable, widely distributed, opensource project. These > projects must employ a full discloser public bug forum. Totally agree on that...which packages of the base LFS system do not qualify? As far as I can tell, lfs-utils, lfs-bootscripts (although pretty trivial) and [place your idea here]... > Installed binary code > Some sort of rating system must be used to validate code trust levels. > Proactive testing, such as bfbtester, source code checking, such as Rats, > and by any other means reasonable. I have tried bfbtester and BOY does it need resources. Any documentation for recommended use? (apart from source) > Minimalization of Root privileges > In any event posible root will not be used to complete systems tasks, or > run daemons. Are we talking about giving the binaries to someother user (bin, for example) and ensuring the SUID bins are kept to a minimum? I'll go for it. I was wondering.....secure means optimised, and optimised leads to fast. Should we take extra steps to provide for an increase in overall efficiency of the system? Not an objective on its own....just when we have to make a choice, speed should be another concern. An efficient system can handle DoSes better than a crawling one. Just a silly suggestion, but I had to take it out. himicos -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page