Re: Secure LFS, SELinux, OpenBSD, LFS 5.x ...
botboy <[email protected]> Fri, 26 Dec 2003 14:48:34 +0200
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Linux From Scratch |
| Message-ID | <[email protected]> |
I never said that they are secure, I only pointed them out in order to give an idea of the work involved... Greets ashes wrote: > On December 25, 2003 01:27 pm, botboy wrote: >> LFS was meant to be an educational purpose implementation of a GNU/Linux >> based operating system. I have difficulty understanding HOW SLFS could be >> something easily integrated into the mainstream LFS. Some library and >> kernel patches cannot possibly account for a completely secure platform, >> although this is a good start. >> >> Take for example what OpenBSD, SELinux have to offer. There is still a >> lot more work to be done, and I fail to understand how a project such as >> the plain LFS could easily integrate all the necessary components. This >> is not what it was built for right? >> >> In anycase every effort that provides us with a better platform is worth >> supporting! >> >> Greets all, the winter.txt hint ROCKS :P > > How do you *know* OpenBSD or SELinux is secure? If you're handling private > information, like credit cards, a single exploit could be the end of your > bussiness. Do you want to take their word for it? If a journalist writes a > story about how secure they are, why should you trust the journalist? > Security has a lot to do with paranioa and trust. When you're paraniod the > only one you trust is yourself. There are some vendors who make wonderfull > claims about security without a foundation for them. They generaly do not > provide us with what we need to verify their claims without doing some > serious (off site) reading, more then most people can tolerate. I think > this is where SLFS can fit in. I don't want to see SLFS full of hot air, > but instead full of proof. > > When SLFS is mature I think it will be dramaticly different then LFS. > Theres a big world of auditing and bug tracking that can fill the pages. I > would like to see report cards for each package describing known bugs and > tolerences to abuse. Something needs to be done about securing user lfs, > and keeping it around after to build other packages. If TCP networking is > going to be part of the base system, then it will need a firewall in the > base system to secure the network. LFS's goals are not the same as SLFS. > LFS had to be made before SLFS could be started. Education is still the > primary goal, but SLFS is beyond the scope of LFS. Unlike LFS, SLFS will > sacrifice some usability for security, and it will be slightly less > minimalistic. SLFS will pick up where LFS drops off. LFS can be used for a > gaming station, server, desktop, etc, and they need to keep that > flexability. SLFS will be more specialized. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page