Re: : SElinux
David Collier-Brown <[email protected]> Mon, 18 Aug 2014 15:24:23 -0400
| Newsgroups | gmane.org.user-groups.linux.tolug |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format. --------------000903000002060800020507 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit To get picky, it was written to prevent breaches of confidentiality, in part so that a sysadmin couldn't just copy everything to a thumb drive and walk away. Because of that, it can protect against a program I run from either snooping on or providing bad data to others, and as a side-effect, keep it from getting more permissions that it minimally needs. Rogue users can be walled off from people, but on Linux, that's been a lower priority than rogue programs. --dave [Double irony: NSA software that helps stop snooping, /and/ it's software they don't use themselves, to stop snooping by insiders] On 08/18/2014 10:19 AM, Bill Thanis wrote: > There are two very different types of security. The first is security > from humans, ie the two examples you gave. The second is security from > malicious or error filled programs. > > SELINUX is mostly about protecting one group of system resources > (files) from processes that could cause it problems. > > Bill > > > > On Fri, Aug 15, 2014 at 11:11 PM, Howard Gibson <[email protected] > <mailto:[email protected]>> wrote: > > On my home computer and laptops, SElinux is a pain in the butt. > > Who is protected by SElinux? Does it protect the system from > rogue users, or does it protect from external crackers? > > -- > Howard Gibson > [email protected] <mailto:[email protected]> > [email protected] <mailto:[email protected]> > [email protected] <mailto:[email protected]> > http://home.eol.ca/~hgibson <http://home.eol.ca/%7Ehgibson> > -- > The Toronto Linux Users Group. Meetings: http://gtalug.org/ > TLUG requests: Linux topics, No HTML, wrap text below 80 columns > How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists > > -- David Collier-Brown, | Always do right. This will gratify System Programmer and Author | some people and astonish the rest [email protected] | -- Mark Twain --------------000903000002060800020507 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <html> <head> <meta content=3D"text/html; charset=3DUTF-8" http-equiv=3D"Content-Ty= pe"> </head> <body text=3D"#000000" bgcolor=3D"#FFFFFF"> <div class=3D"moz-cite-prefix">To get picky, it was written to preven= t breaches of confidentiality, in part so that a sysadmin couldn't just copy everything to a thumb drive and walk away.=C2=A0 <br> <br> Because of that, it can protect against a program I run from either snooping on or providing bad data to others, and as a side-effect, keep it from getting more permissions that it minimally needs.<br> <br> Rogue users can be walled off from people, but on Linux, that's been a lower priority than rogue programs. <br> <br> --dave<br> [Double irony: NSA software that helps stop snooping, <i>and</i> it's software they don't use themselves, to stop snooping by insiders]<br> <br> <br> On 08/18/2014 10:19 AM, Bill Thanis wrote:<br> </div> <blockquote cite=3D"mid:CAA3RLT6KMfBZH7GOEzr9OUnLbPidrfa4bUmPxmY9LBFTGzDp3w-JsoAwUIsXov1KXRcyAk9cg@public.gmane.org= l.com" type=3D"cite"> <div dir=3D"ltr"> <div> <div>There are two very different types of security. The first is security from humans, ie the two examples you gave. The second is security from malicious or error filled programs.<b= r> <br> </div> SELINUX is mostly about protecting one group of system resources (files) from processes that could cause it problems.<= br> <br> </div> Bill<br> <br> </div> <div class=3D"gmail_extra"><br> <br> <div class=3D"gmail_quote">On Fri, Aug 15, 2014 at 11:11 PM, Howard Gibson <span dir=3D"ltr"><<a moz-do-not-send=3D"true" href=3D"mailto:[email protected]" target=3D"_blank">hgibson@eo= l.ca</a>></span> wrote:<br> <blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">=C2=A0 =C2=A0= On my home computer and laptops, SElinux is a pain in the butt.<br> <br> =C2=A0 =C2=A0Who is protected by SElinux?=C2=A0 Does it prote= ct the system from rogue users, or does it protect from external crackers?<= br> <span class=3D"HOEnZb"><font color=3D"#888888"><br> --<br> Howard Gibson<br> <a moz-do-not-send=3D"true" href=3D"mailto:[email protected]= ">[email protected]</a><br> <a moz-do-not-send=3D"true" href=3D"mailto:[email protected]">howard.gibson@= optech.com</a><br> <a moz-do-not-send=3D"true" href=3D"mailto:[email protected]">jhowardgibson@g= mail.com</a><br> <a moz-do-not-send=3D"true" href=3D"http://home.eol.ca/%7Ehgibson" target=3D"_blank= ">http://home.eol.ca/~hgibson</a><br> --<br> The Toronto Linux Users Group.=C2=A0 =C2=A0 =C2=A0 Meetin= gs: <a moz-do-not-send=3D"true" href=3D"http://gtalug.org/" target=3D"_blank">http://gtalug.org/</a><br> TLUG requests: Linux topics, No HTML, wrap text below 80 columns<br> How to UNSUBSCRIBE: <a moz-do-not-send=3D"true" href=3D"http://gtalug.org/wiki/Mailing_lists" target=3D"_blank">http://gtalug.org/wiki/Mailing_lists<= /a><br> </font></span></blockquote> </div> <br> </div> </blockquote> <br> <br> <pre class=3D"moz-signature" cols=3D"72">--=20 David Collier-Brown, | Always do right. This will gratify System Programmer and Author | some people and astonish the rest <a class=3D"moz-txt-link-abbreviated" href=3D"mailto:[email protected]">= [email protected]</a> | -- Mark Twain </pre> </body> </html> --------------000903000002060800020507-- -- The Toronto Linux Users Group. Meetings: http://gtalug.org/ TLUG requests: Linux topics, No HTML, wrap text below 80 columns How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists