Gentoo Archives: gentoo-hardened

From: Brian Davis <bridavis@×××××××.net>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Do I need RBAC?
Date: Sun, 29 Oct 2006 17:44:01
Message-Id: 001001c6fb81$7b70f0b0$0201a8c0@ne.mediaone.net
In Reply to: Re: [gentoo-hardened] Re: Do I need RBAC? by atoth@atoth.sote.hu
1 So maybe I'm missing something. Is learning mode all you need to do to get
2 up and running? How much time did you spend tweaking the profile? Is it a
3 security no-no to ask to see your profile.
4
5 Thanks,
6 Brian
7
8 ----- Original Message -----
9 From: <atoth@××××××××××.hu>
10 To: <gentoo-hardened@l.g.o>
11 Sent: Sunday, October 29, 2006 11:37 AM
12 Subject: Re: [gentoo-hardened] Re: Do I need RBAC?
13
14
15 > On Vas, Október 29, 2006 16:19, 7v5w7go9ub0o wrote:
16 >> If you are talking about Grsecurity (which has a learning mode that makes
17 >> configuration very easy), and if your users are doing limited, standard
18 >> things, then a strong Yes! (though IIUC, SeLinux is difficult to
19 >> configure)
20 > Strongly agree.
21 >
22 > I use Grsecurity even on my laptop, which has only one non-root user: me.
23 > You can call me paranoid, but it's good to know, that my computer is
24 > protected from myself...
25 >
26 > Regards,
27 > Dw.
28 >
29 > --
30 > dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057,
31 > 06-30-5962-962
32 > Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
33 >
34 >>
35 >> The RBAC protection will protect you if -you- or a trusted user does
36 >> something accidentally (e.g. shell command), or downloads something that
37 >> tries to exploit a news client or browser. It may also protect you if
38 >> someone ever compromises a portage distribution.
39 >>
40 >> There seems to be a reluctance among some old-timers to use the hardened
41 >> tools anywhere else but on a server - I'd guess that is a holdover from
42 >> the last decade when both Linux and the hardening tools were being
43 >> created. Today's (non-selinux) tools are easy to use, and are IMHO quite
44 >> appropriate for home use in today's world of professional crackers going
45 >> after home users. Heh, even MS is "hardening" their new OS, VISTA.
46 >>
47 >>
48 >> On Sun, 29 Oct 2006 00:16:59 -0400,
49 >> <bridavis-Wuw85uim5zDR7s880joybQ@××××××××××××.org> wrote:
50 >>
51 >>> I have a total of 3 non-root users, 1 is me, the 2 others are trusted
52 >>> (i.e. family/friend). RBAC looks like it's more complex that I need and
53 >>> want to deal with, and I'm I'm wondering if I should bother with this
54 >>> with so few users.
55 >>>
56 >>> Thoughts?
57 >>>
58 >>> Thanks,
59 >>> Brian
60 >>
61 >>
62 >> --
63 >> gentoo-hardened@g.o mailing list
64 >>
65 >
66 >
67 > --
68 > gentoo-hardened@g.o mailing list
69 >
70
71 --
72 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Re: Do I need RBAC? Brant Williams <brant@×××××.net>