login
Header Space

 
 

Re: Defense in depth: LSM *modules*, not a static interface

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Peter Dolding <oiaohm@...>
Cc: Crispin Cowan <crispin@...>, Simon Arlott <simon@...>, <linux-kernel@...>, <linux-security-module@...>
Date: Tuesday, November 6, 2007 - 11:50 pm

As good an idea POSIX capabilities might be, not all security problems 
can be solved with a bitmap of on/off permissions.

Peter Dolding wrote:

Ok but what happens to the principle of least privilege?

What if we want AppArmor to confine that application to use a particular 
set of ports?

Do you propose having a capability for each port? how about protocols?

So unless my understanding of capabilities is fundamentally flawed 
(which it may be - I have not spent time reviewing recent changes) 
obviously Linux capabilities does not provide a solution to every problem.

Regards,

Cliffe.

--

Z. Cliffe Schreuders
BSc Comp Sci (Hons) & Int Comp
PhD Candidate, Casual Tutor
School of IT
Murdoch University
-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Defense in depth: LSM *modules*, not a static interface, Cliffe, (Tue Nov 6, 11:50 pm)
Re: Defense in depth: LSM *modules*, not a static interface, Casey Schaufler, (Tue Nov 6, 11:35 pm)
Re: Defense in depth: LSM *modules*, not a static interface, Casey Schaufler, (Wed Nov 7, 12:34 am)
Re: Defense in depth: LSM *modules*, not a static interface, Casey Schaufler, (Tue Oct 30, 11:01 am)
speck-geostationary