Gentoo Archives: gentoo-dev

From: Ciaran McCreesh <ciaran.mccreesh@××××××××××.com>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: RFC: enabling ipc-sandbox & network-sandbox by default
Date: Thu, 15 May 2014 18:44:44
Message-Id: 20140515194431.36e66911@googlemail.com
In Reply to: Re: [gentoo-dev] Re: RFC: enabling ipc-sandbox & network-sandbox by default by "Thomas D."
1 On Thu, 15 May 2014 20:35:41 +0200
2 "Thomas D." <whissi@××××××.de> wrote:
3 > Ciaran McCreesh wrote:
4 > > Sandboxing isn't about security. It's about catching mistakes.
5 >
6 > From Wikipedia
7 > (http://en.wikipedia.org/wiki/Sandbox_%28computer_security%29):
8 > > In computer security, a sandbox is a security mechanism for
9 > > separating running programs. It is often used to execute untested
10 > > code, or untrusted programs from unverified third-parties,
11 > > suppliers, untrusted users and untrusted websites
12 >
13 > network-sandbox is using unshare() syscalls to separate... not?
14
15 Not for security reasons: sandbox (the way it is used on Gentoo) does
16 nothing against a malicious ebuild or a malicious package. Instead, it
17 simply catches certain common mistakes.
18
19 --
20 Ciaran McCreesh

Attachments

File name MIME type
signature.asc application/pgp-signature