Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory Access Control Kernel

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Theodore Tso <tytso@...>
Cc: Joshua Brindle <method@...>, Andrew Morton <akpm@...>, <casey@...>, <torvalds@...>, <linux-security-module@...>, <linux-kernel@...>, James Morris <jmorris@...>, Paul Moore <paul.moore@...>
Date: Sunday, September 30, 2007 - 4:05 pm

> Yes, normally the network is outside the Trusted Computing Base (TCB),

Normally as in the 99.99999% case.


PCI busses normally don't have routers to networks outside the box connected
to them. 


With your argumentation we could also just disable all security
in these situations (as in null LSM to save some overhead); after all these 
systems are protected by armed guards.  If someone gets past the guards
they could connect their laptop to the network and fake all the "secured"
packets. If you assume that won't happen why do you need computer security at all?

Anyways; if someone wants to cripple their security for some
performance this way they can surely do this; but i don't think we should 
offer it as a default configuration option (just as we don't have a 
CONFIG_NULL_LSM even though there are undoubtedly systems that don't
care about permission checking[1]) 

-Andi

[1] I bet I gave the linux-tiny crowd an idea now ;-)

-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Eric W. Biederman, (Fri Oct 5, 12:45 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Kazuki Omo(Company), (Tue Oct 30, 12:01 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Eric W. Biederman, (Wed Oct 10, 9:48 am)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Andi Kleen, (Sun Sep 30, 4:05 pm)
Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandato..., Christoph Hellwig, (Sun Sep 30, 5:53 am)