Re: OBSD's perspective on SELinux

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Darren Spruell
Date: Monday, September 24, 2007 - 1:48 pm

On 9/24/07, ttw+bsd@cobbled.net <ttw+bsd@cobbled.net> wrote:

Oh, that sounds like a recipe for success.

- Run _arbitrary_ _binary_ application on system. Intend to use policy
wrapper to restrict to allowed operations.
- Can't figure out how to get a working policy (made harder because
you can't debug the damn blob well anyway). (made harder because the
ppl who sold you that application aren't going to be able to help you
when you ask them "why is this app doing X Y and Z?" when X Y and Z
are system calls they've never heard of.)
- So, disable policy stuff or just "allow all" just to get it working.
Face it; the fact that you're running the dumb binary app in the first
place is because its so critical you can't do without it. Given the
choice between having a mission critical app (that you probably paid
good money for) crippled by the policy layer or not having to deal
with it, what are people going to do?

The intentions are great and look good on paper. The reality is a bit
different, as others have pointed out.

DS
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: OBSD's perspective on SELinux, Can E. Acar, (Mon Sep 24, 11:49 am)
Re: OBSD's perspective on SELinux, ttw+bsd, (Mon Sep 24, 1:13 pm)
Re: OBSD's perspective on SELinux, Darren Spruell, (Mon Sep 24, 1:48 pm)
Re: OBSD's perspective on SELinux, Rui Miguel Silva Seabra, (Mon Sep 24, 1:52 pm)
Re: OBSD's perspective on SELinux, Luke Bakken, (Mon Sep 24, 2:28 pm)
Re: OBSD's perspective on SELinux, ttw+bsd, (Mon Sep 24, 5:34 pm)
Re: OBSD's perspective on SELinux, ttw+bsd, (Mon Sep 24, 5:40 pm)
Re: OBSD's perspective on SELinux, Tony Abernethy, (Mon Sep 24, 6:06 pm)
Re: OBSD's perspective on SELinux, Todd Alan Smith, (Mon Sep 24, 6:32 pm)
Re: OBSD's perspective on SELinux , Marco S Hyman, (Mon Sep 24, 8:26 pm)