Re: Secure LFS, SELinux, OpenBSD, LFS 5.x ...
ashes <[email protected]> Thu, 25 Dec 2003 15:32:14 -0500
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Utopia Inc |
| Message-ID | <[email protected]> |
On December 25, 2003 01:27 pm, botboy wrote: > LFS was meant to be an educational purpose implementation of a GNU/Linux > based operating system. I have difficulty understanding HOW SLFS could be > something easily integrated into the mainstream LFS. Some library and > kernel patches cannot possibly account for a completely secure platform, > although this is a good start. > > Take for example what OpenBSD, SELinux have to offer. There is still a lot > more work to be done, and I fail to understand how a project such as the > plain LFS could easily integrate all the necessary components. This is not > what it was built for right? > > In anycase every effort that provides us with a better platform is worth > supporting! > > Greets all, the winter.txt hint ROCKS :P How do you *know* OpenBSD or SELinux is secure? If you're handling private information, like credit cards, a single exploit could be the end of your bussiness. Do you want to take their word for it? If a journalist writes a story about how secure they are, why should you trust the journalist? Security has a lot to do with paranioa and trust. When you're paraniod the only one you trust is yourself. There are some vendors who make wonderfull claims about security without a foundation for them. They generaly do not provide us with what we need to verify their claims without doing some serious (off site) reading, more then most people can tolerate. I think this is where SLFS can fit in. I don't want to see SLFS full of hot air, but instead full of proof. When SLFS is mature I think it will be dramaticly different then LFS. Theres a big world of auditing and bug tracking that can fill the pages. I would like to see report cards for each package describing known bugs and tolerences to abuse. Something needs to be done about securing user lfs, and keeping it around after to build other packages. If TCP networking is going to be part of the base system, then it will need a firewall in the base system to secure the network. LFS's goals are not the same as SLFS. LFS had to be made before SLFS could be started. Education is still the primary goal, but SLFS is beyond the scope of LFS. Unlike LFS, SLFS will sacrifice some usability for security, and it will be slightly less minimalistic. SLFS will pick up where LFS drops off. LFS can be used for a gaming station, server, desktop, etc, and they need to keep that flexability. SLFS will be more specialized. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page