Re: OBSD's perspective on SELinux

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Saturday, September 22, 2007 - 4:39 pm

On Sat, Sep 22, 2007 at 07:45:57PM +0300, Ihar Hrachyshka wrote:

> What part of SELinux is NOT Unix? Remember that all traditional Unix

Insofar as that ls -la shows them, yes. In the sense that files actually
work that way, `usually'.

> > Additionally, it's not entirely clear whether it actually helps;

Root almost always can gain complete control over the system anyway, so
that's not a big issue.

Also see my comments below.

Still, yes, SELinux can be - rarely - used to solve problems for which
no clean UNIX-ish solution exists. Far too often, though, it's thought
of a as a magic bullet, which it certainly is not.

> > SELinux configuration is, even at its best, a lot more complex than the

Yes, but not all code is created equal. Layering a second permission
layer into the system integrates closely with all other security
mechanisms, which is more dangerous than yet another driver.

Additionally, it's completely the wrong way to go about securing a
system. The best way not to have any vulnerabilities is not to have any
vulnerabilities; stuff like SELinux, Pax, or W^X is cool, but not a
substitute for good programming. An OpenBSD system running properly
chosen and secured programs without W^X is almost as secure as one with
it. I'd argue the same goes a Linux system running a haphazard
collection of badly-out-of-date, unpatched monstrosities with or without
SELinux.

Finally, SELinux is almost never necessary. (But it *is* - rarely -
useful.) And takes a lot of time, which is usually better spent doing
something actually useful - like log monitoring.

Joachim

--
TFMotD: packages-specs (7) - binary package names specifications

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 11:34 am)
Re: OBSD's perspective on SELinux, Damien Miller, (Mon Sep 24, 11:09 pm)
Re: OBSD's perspective on SELinux, Chris Kuethe, (Mon Sep 24, 10:52 am)
Re: OBSD's perspective on SELinux, Marco Peereboom, (Sat Sep 22, 11:27 pm)
Re: OBSD's perspective on SELinux, L. V. Lammert, (Sat Sep 22, 7:47 pm)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Sun Sep 23, 5:54 pm)
Re: OBSD's perspective on SELinux, Ted Unangst, (Mon Sep 24, 1:29 pm)
Re: OBSD's perspective on SELinux, Jacob Yocom-Piatt, (Mon Sep 24, 2:17 pm)
Re: OBSD's perspective on SELinux, Ted Unangst, (Mon Sep 24, 3:14 pm)
Re: OBSD's perspective on SELinux, Brian Candler, (Mon Sep 24, 11:31 am)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Mon Sep 24, 11:59 am)
Re: OBSD's perspective on SELinux, Marc Espie, (Tue Sep 25, 6:06 am)
Re: OBSD's perspective on SELinux, Marc Espie, (Tue Sep 25, 8:34 am)
Re: digitally signed distribution (was: OBSD's perspective o..., Martin Schröder, (Mon Sep 24, 11:18 am)
Re: digitally signed distribution (was: OBSD's perspective o..., Martin Schröder, (Mon Sep 24, 12:02 pm)
Re: digitally signed distribution (was: OBSD's perspective o..., Rui Miguel Silva Seabra, (Sun Sep 23, 6:38 pm)
Re: OBSD's perspective on SELinux, Ted Unangst, (Sat Sep 22, 2:50 pm)
Re: OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 4:21 pm)
Re: OBSD's perspective on SELinux, , (Sat Sep 22, 7:20 pm)
Re: OBSD's perspective on SELinux, Stuart Henderson, (Sat Sep 22, 4:00 pm)
Re: OBSD's perspective on SELinux, Joachim Schipper, (Sat Sep 22, 12:29 pm)
Re: OBSD's perspective on SELinux, Ihar Hrachyshka, (Sat Sep 22, 12:45 pm)
Re: OBSD's perspective on SELinux, Joachim Schipper, (Sat Sep 22, 4:39 pm)
Re: OBSD's perspective on SELinux, Darrin Chandler, (Sat Sep 22, 12:00 pm)
Re: OBSD's perspective on SELinux, Eduardo Tongson, (Sat Sep 22, 12:52 pm)
Re: OBSD's perspective on SELinux, Jason Dixon, (Sat Sep 22, 12:20 pm)
Re: OBSD's perspective on SELinux, Douglas A. Tutty, (Sat Sep 22, 1:21 pm)
Re: OBSD's perspective on SELinux, Ihar Hrachyshka, (Sat Sep 22, 1:38 pm)
Re: OBSD's perspective on SELinux, David Gwynne, (Mon Sep 24, 10:08 am)
Re: OBSD's perspective on SELinux, Jason Dixon, (Mon Sep 24, 10:25 am)
Re: OBSD's perspective on SELinux, , (Mon Sep 24, 2:28 pm)
Re: OBSD's perspective on SELinux, Brian Candler, (Sun Sep 23, 3:25 pm)
Re: OBSD's perspective on SELinux, Eduardo Tongson, (Sat Sep 22, 2:00 pm)
Re: OBSD's perspective on SELinux, Jeffrey 'jf' Lim, (Sat Sep 22, 12:26 pm)