Gentoo Archives: gentoo-hardened

From: Panagiotis Atmatzidis <p.atmatzidis@×××××.com>
To: gentoo-hardened@l.g.o
Cc: bridavis@×××××××.net
Subject: Re: [gentoo-hardened] Do I need RBAC?
Date: Sun, 29 Oct 2006 12:12:31
Message-Id: 45449B01.60109@gmail.com
In Reply to: Re: [gentoo-hardened] Do I need RBAC? by Guillaume Castagnino
1 Guillaume Castagnino wrote:
2 > Hi,
3 >
4 > hardening is not only to protect against your known users, but only from
5 > external attackers !
6 > If you have a flaw in one of your servers that can be remotely
7 > exploited, hardening your box will help you containing the attacker !
8 >
9 > Regards,
10 >
11 > Le dimanche 29 octobre 2006 05:16, bridavis@×××××××.net a écrit :
12 >> I have a total of 3 non-root users, 1 is me, the 2 others are trusted
13 >> (i.e. family/friend). RBAC looks like it's more complex that I need
14 >> and want to deal with, and I'm I'm wondering if I should bother with
15 >> this with so few users.
16 >>
17 >> Thoughts?
18 >>
19 >> Thanks,
20 >> Brian
21 >
22
23 I replied before with a straight answer. My case is the case of a "kid"
24 (24 old) who likes to play with his computer so he applies
25 hardened&RSBAC now and then, set ups snort and plays with security-wise
26 system configuration (encryption etc) as much as time and will permits.
27
28 That said, there is no need for someone to set up a box like that just
29 for being "secure". The trade off imho is too much. Remember that for an
30 expert hacker a misconfiguration is enough to take over the system. A
31 hardened system takes time and brainpower to be set up correctly.
32
33 I see no point to apply orange-book security level on a standard systems
34 by default.
35
36
37 Cheers.
38 --
39 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Do I need RBAC? Guillaume Castagnino <casta@×××××.info>