1 |
So maybe I'm missing something. Is learning mode all you need to do to get |
2 |
up and running? How much time did you spend tweaking the profile? Is it a |
3 |
security no-no to ask to see your profile. |
4 |
|
5 |
Thanks, |
6 |
Brian |
7 |
|
8 |
----- Original Message ----- |
9 |
From: <atoth@××××××××××.hu> |
10 |
To: <gentoo-hardened@l.g.o> |
11 |
Sent: Sunday, October 29, 2006 11:37 AM |
12 |
Subject: Re: [gentoo-hardened] Re: Do I need RBAC? |
13 |
|
14 |
|
15 |
> On Vas, Október 29, 2006 16:19, 7v5w7go9ub0o wrote: |
16 |
>> If you are talking about Grsecurity (which has a learning mode that makes |
17 |
>> configuration very easy), and if your users are doing limited, standard |
18 |
>> things, then a strong Yes! (though IIUC, SeLinux is difficult to |
19 |
>> configure) |
20 |
> Strongly agree. |
21 |
> |
22 |
> I use Grsecurity even on my laptop, which has only one non-root user: me. |
23 |
> You can call me paranoid, but it's good to know, that my computer is |
24 |
> protected from myself... |
25 |
> |
26 |
> Regards, |
27 |
> Dw. |
28 |
> |
29 |
> -- |
30 |
> dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, |
31 |
> 06-30-5962-962 |
32 |
> Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962 |
33 |
> |
34 |
>> |
35 |
>> The RBAC protection will protect you if -you- or a trusted user does |
36 |
>> something accidentally (e.g. shell command), or downloads something that |
37 |
>> tries to exploit a news client or browser. It may also protect you if |
38 |
>> someone ever compromises a portage distribution. |
39 |
>> |
40 |
>> There seems to be a reluctance among some old-timers to use the hardened |
41 |
>> tools anywhere else but on a server - I'd guess that is a holdover from |
42 |
>> the last decade when both Linux and the hardening tools were being |
43 |
>> created. Today's (non-selinux) tools are easy to use, and are IMHO quite |
44 |
>> appropriate for home use in today's world of professional crackers going |
45 |
>> after home users. Heh, even MS is "hardening" their new OS, VISTA. |
46 |
>> |
47 |
>> |
48 |
>> On Sun, 29 Oct 2006 00:16:59 -0400, |
49 |
>> <bridavis-Wuw85uim5zDR7s880joybQ@××××××××××××.org> wrote: |
50 |
>> |
51 |
>>> I have a total of 3 non-root users, 1 is me, the 2 others are trusted |
52 |
>>> (i.e. family/friend). RBAC looks like it's more complex that I need and |
53 |
>>> want to deal with, and I'm I'm wondering if I should bother with this |
54 |
>>> with so few users. |
55 |
>>> |
56 |
>>> Thoughts? |
57 |
>>> |
58 |
>>> Thanks, |
59 |
>>> Brian |
60 |
>> |
61 |
>> |
62 |
>> -- |
63 |
>> gentoo-hardened@g.o mailing list |
64 |
>> |
65 |
> |
66 |
> |
67 |
> -- |
68 |
> gentoo-hardened@g.o mailing list |
69 |
> |
70 |
|
71 |
-- |
72 |
gentoo-hardened@g.o mailing list |