1 |
-----BEGIN PGP SIGNED MESSAGE----- |
2 |
Hash: SHA1 |
3 |
|
4 |
On Tuesday 18 March 2003 18:53, Sven Vermeulen wrote: |
5 |
> On Tue, Mar 18, 2003 at 11:44:32AM -0600, nick anderson wrote: |
6 |
> > what about the lids project? |
7 |
> |
8 |
> Hmmm, from their website: |
9 |
> |
10 |
> """ |
11 |
> 2.4 series development version LIDS 1.0.9 for 2.4.5 is out. |
12 |
> Fri Jun 1 09:31:52 CST 2001 |
13 |
> """ |
14 |
> |
15 |
> So it's not very actively developed. Furthermore I think that LIDS is |
16 |
> more of a kernelpatch to integrate easier with the daemons that the |
17 |
> project provides, and it is, as the name sais, an Intrusion Detection |
18 |
> System. |
19 |
|
20 |
I'd have to disagree. First of all - the latest news aren't on the bottom of |
21 |
the page ;) |
22 |
|
23 |
Second - which daemons are you talking about? I've been working pretty |
24 |
closely with the LIDS devels for a while, and the last time I checked it |
25 |
was a MAC system which didn't ship with any daemons. Are you sure you |
26 |
aren't thinking of a different project? |
27 |
|
28 |
My biggest concern with LIDS is its design. It's still inode based, right? |
29 |
IMO, systrace and grsecurity ACLs solve the same problems as LIDS in a much |
30 |
more elegant fashion. |
31 |
|
32 |
> But don't forget what gentoo-hardened is all about: it's not solely |
33 |
> implementing SELinux in Gentoo, it's all about security, so having |
34 |
> LIDS-support (and others) isn't out of the question. |
35 |
|
36 |
Indeed, if someone's willing to do the hard work :) |
37 |
|
38 |
- -- |
39 |
Joachim Blaabjerg |
40 |
Gentoo Linux Security Developer |
41 |
GPG key @ http://cvs.gentoo.org/~styx |
42 |
-----BEGIN PGP SIGNATURE----- |
43 |
Version: GnuPG v1.2.1 (GNU/Linux) |
44 |
|
45 |
iD8DBQE+d19qFJKdDpq6hFsRAl+lAJwK3x64v3bH/P8STVD7X6ve0EcnMACfU+ze |
46 |
hzWUs4ofv7SEct2cv9Gyjms= |
47 |
=3ogB |
48 |
-----END PGP SIGNATURE----- |
49 |
|
50 |
|
51 |
-- |
52 |
gentoo-hardened@g.o mailing list |