Re: Secure LFS, SELinux, OpenBSD, LFS 5.x ...

ashes <[email protected]> Thu, 25 Dec 2003 15:32:14 -0500
Newsgroups gmane.linux.lfs.security
Organization Utopia Inc
Message-ID <[email protected]>
On December 25, 2003 01:27 pm, botboy wrote:
> LFS was meant to be an educational purpose implementation of a GNU/Linux
> based operating system. I have difficulty understanding HOW SLFS could be
> something easily integrated into the mainstream LFS. Some library and
> kernel patches cannot possibly account for a completely secure platform,
> although this is a good start.
>
> Take for example what OpenBSD, SELinux have to offer. There is still a lot
> more work to be done, and I fail to understand how a project such as the
> plain LFS could easily integrate all the necessary components. This is not
> what it was built for right?
>
> In anycase every effort that provides us with a better platform is worth
> supporting!
>
> Greets all, the winter.txt hint ROCKS :P

How do you *know* OpenBSD or SELinux is secure? If you're handling private 
information, like credit cards, a single exploit could be the end of your 
bussiness. Do you want to take their word for it? If a journalist writes a 
story about how secure they are, why should you trust the journalist? 
Security has a lot to do with paranioa and trust. When you're paraniod the 
only one you trust is yourself. There are some vendors who make wonderfull 
claims about security without a foundation for them. They generaly do not 
provide us with what we need to verify their claims without doing some 
serious (off site) reading, more then most people can tolerate. I think this 
is where SLFS can fit in. I don't want to see SLFS full of hot air, but 
instead full of proof.

When SLFS is mature I think it will be dramaticly different then LFS. Theres a 
big world of auditing and bug tracking that can fill the pages. I would like 
to see report cards for each package describing known bugs and tolerences to 
abuse. Something needs to be done about securing user lfs, and keeping it 
around after to build other packages. If TCP networking is going to be part 
of the base system, then it will need a firewall in the base system to secure 
the network. LFS's goals are not the same as SLFS. LFS had to be made before 
SLFS could be started. Education is still the primary goal, but SLFS is 
beyond the scope of LFS. Unlike LFS, SLFS will sacrifice some usability for 
security, and it will be slightly less minimalistic. SLFS will pick up where 
LFS drops off. LFS can be used for a gaming station, server, desktop, etc, 
and they need to keep that flexability. SLFS will be more specialized.


-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page