Re: Secure LFS, SELinux, OpenBSD, LFS 5.x ...

botboy <[email protected]> Fri, 26 Dec 2003 14:48:34 +0200
Newsgroups gmane.linux.lfs.security
Organization Linux From Scratch
Message-ID <[email protected]>
I never said  that they are secure, I only pointed them out in order to give
an idea of the work involved...

Greets

ashes wrote:

> On December 25, 2003 01:27 pm, botboy wrote:
>> LFS was meant to be an educational purpose implementation of a GNU/Linux
>> based operating system. I have difficulty understanding HOW SLFS could be
>> something easily integrated into the mainstream LFS. Some library and
>> kernel patches cannot possibly account for a completely secure platform,
>> although this is a good start.
>>
>> Take for example what OpenBSD, SELinux have to offer. There is still a
>> lot more work to be done, and I fail to understand how a project such as
>> the plain LFS could easily integrate all the necessary components. This
>> is not what it was built for right?
>>
>> In anycase every effort that provides us with a better platform is worth
>> supporting!
>>
>> Greets all, the winter.txt hint ROCKS :P
> 
> How do you *know* OpenBSD or SELinux is secure? If you're handling private
> information, like credit cards, a single exploit could be the end of your
> bussiness. Do you want to take their word for it? If a journalist writes a
> story about how secure they are, why should you trust the journalist?
> Security has a lot to do with paranioa and trust. When you're paraniod the
> only one you trust is yourself. There are some vendors who make wonderfull
> claims about security without a foundation for them. They generaly do not
> provide us with what we need to verify their claims without doing some
> serious (off site) reading, more then most people can tolerate. I think
> this is where SLFS can fit in. I don't want to see SLFS full of hot air,
> but instead full of proof.
> 
> When SLFS is mature I think it will be dramaticly different then LFS.
> Theres a big world of auditing and bug tracking that can fill the pages. I
> would like to see report cards for each package describing known bugs and
> tolerences to abuse. Something needs to be done about securing user lfs,
> and keeping it around after to build other packages. If TCP networking is
> going to be part of the base system, then it will need a firewall in the
> base system to secure the network. LFS's goals are not the same as SLFS.
> LFS had to be made before SLFS could be started. Education is still the
> primary goal, but SLFS is beyond the scope of LFS. Unlike LFS, SLFS will
> sacrifice some usability for security, and it will be slightly less
> minimalistic. SLFS will pick up where LFS drops off. LFS can be used for a
> gaming station, server, desktop, etc, and they need to keep that
> flexability. SLFS will be more specialized.

-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page