Gentoo Archives: gentoo-hardened

From: atoth@××××××××××.hu
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Do I need RBAC?
Date: Sun, 29 Oct 2006 16:55:20
Message-Id: 57040.195.111.75.211.1162139873.squirrel@atoth.sote.hu
In Reply to: [gentoo-hardened] Re: Do I need RBAC? by 7v5w7go9ub0o <7v5w7go9ub0o@gmail.com>
1 On Vas, Október 29, 2006 16:19, 7v5w7go9ub0o wrote:
2 > If you are talking about Grsecurity (which has a learning mode that makes
3 > configuration very easy), and if your users are doing limited, standard
4 > things, then a strong Yes! (though IIUC, SeLinux is difficult to
5 > configure)
6 Strongly agree.
7
8 I use Grsecurity even on my laptop, which has only one non-root user: me.
9 You can call me paranoid, but it's good to know, that my computer is
10 protected from myself...
11
12 Regards,
13 Dw.
14
15 --
16 dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962
17 Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
18
19 >
20 > The RBAC protection will protect you if -you- or a trusted user does
21 > something accidentally (e.g. shell command), or downloads something that
22 > tries to exploit a news client or browser. It may also protect you if
23 > someone ever compromises a portage distribution.
24 >
25 > There seems to be a reluctance among some old-timers to use the hardened
26 > tools anywhere else but on a server - I'd guess that is a holdover from
27 > the last decade when both Linux and the hardening tools were being
28 > created. Today's (non-selinux) tools are easy to use, and are IMHO quite
29 > appropriate for home use in today's world of professional crackers going
30 > after home users. Heh, even MS is "hardening" their new OS, VISTA.
31 >
32 >
33 > On Sun, 29 Oct 2006 00:16:59 -0400,
34 > <bridavis-Wuw85uim5zDR7s880joybQ@××××××××××××.org> wrote:
35 >
36 >> I have a total of 3 non-root users, 1 is me, the 2 others are trusted
37 >> (i.e. family/friend). RBAC looks like it's more complex that I need and
38 >> want to deal with, and I'm I'm wondering if I should bother with this
39 >> with so few users.
40 >>
41 >> Thoughts?
42 >>
43 >> Thanks,
44 >> Brian
45 >
46 >
47 > --
48 > gentoo-hardened@g.o mailing list
49 >
50
51
52 --
53 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Re: Do I need RBAC? Brian Davis <bridavis@×××××××.net>