Re: Preview of changes to the Security susbystem for 2.6.36

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Kees Cook
Date: Tuesday, August 3, 2010 - 7:55 pm

On Tue, Aug 03, 2010 at 10:07:55PM -0400, Valdis.Kletnieks@vt.edu wrote:

Well, Yama is just an LSM. The symlink/hardlink thing has been around
forever and does sufficiently solve the general symlink race flaw. But,
whatever, we disagree about this.


Well, it drastically reduces the urgency of such a vulnerability. Besides,
if this makes a million systems safer and 1 less safe, that's still a
net win.


I'm not convinced. I see what you're trying to say, but I just don't agree.
The symlink/hardlink thing is a tiny corner case of the operational
conditions under which DAC operates, and this is fixing a mistake in the
design that leads programmers into a (well known but seemingly unavoidable)
trap.


Yeah, my next trick will be helping people confine their web applications.
Hahaha ugh. That's an area of endless poor choices.


We'll agree to disagree. And at the same time I'll point out that if
SELinux is off (or app is running without policy), symlink races are just
as bad.


alt.ptrace.die.die.die


Perhaps later. For the moment, I'm happy with my racey anti-PTRACE
solution.

-Kees

-- 
Kees Cook
Ubuntu Security Team
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Preview of changes to the Security susbystem for 2.6.36, James Morris, (Fri Jul 30, 1:59 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Mon Aug 2, 3:19 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christoph Hellwig, (Mon Aug 2, 5:24 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Serge E. Hallyn, (Mon Aug 2, 11:08 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Mon Aug 2, 11:50 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Mon Aug 2, 11:51 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 2:38 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Tue Aug 3, 2:52 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 7:07 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Kees Cook, (Tue Aug 3, 7:55 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Tue Aug 3, 11:18 pm)
Re: Preview of changes to the Security susbystem for 2.6.36, Christian Stroetmann, (Wed Aug 4, 5:21 am)
Re: Preview of changes to the Security susbystem for 2.6.36, Valdis.Kletnieks, (Wed Aug 4, 9:23 am)