1 |
On Vas, Október 29, 2006 16:19, 7v5w7go9ub0o wrote: |
2 |
> If you are talking about Grsecurity (which has a learning mode that makes |
3 |
> configuration very easy), and if your users are doing limited, standard |
4 |
> things, then a strong Yes! (though IIUC, SeLinux is difficult to |
5 |
> configure) |
6 |
Strongly agree. |
7 |
|
8 |
I use Grsecurity even on my laptop, which has only one non-root user: me. |
9 |
You can call me paranoid, but it's good to know, that my computer is |
10 |
protected from myself... |
11 |
|
12 |
Regards, |
13 |
Dw. |
14 |
|
15 |
-- |
16 |
dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962 |
17 |
Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962 |
18 |
|
19 |
> |
20 |
> The RBAC protection will protect you if -you- or a trusted user does |
21 |
> something accidentally (e.g. shell command), or downloads something that |
22 |
> tries to exploit a news client or browser. It may also protect you if |
23 |
> someone ever compromises a portage distribution. |
24 |
> |
25 |
> There seems to be a reluctance among some old-timers to use the hardened |
26 |
> tools anywhere else but on a server - I'd guess that is a holdover from |
27 |
> the last decade when both Linux and the hardening tools were being |
28 |
> created. Today's (non-selinux) tools are easy to use, and are IMHO quite |
29 |
> appropriate for home use in today's world of professional crackers going |
30 |
> after home users. Heh, even MS is "hardening" their new OS, VISTA. |
31 |
> |
32 |
> |
33 |
> On Sun, 29 Oct 2006 00:16:59 -0400, |
34 |
> <bridavis-Wuw85uim5zDR7s880joybQ@××××××××××××.org> wrote: |
35 |
> |
36 |
>> I have a total of 3 non-root users, 1 is me, the 2 others are trusted |
37 |
>> (i.e. family/friend). RBAC looks like it's more complex that I need and |
38 |
>> want to deal with, and I'm I'm wondering if I should bother with this |
39 |
>> with so few users. |
40 |
>> |
41 |
>> Thoughts? |
42 |
>> |
43 |
>> Thanks, |
44 |
>> Brian |
45 |
> |
46 |
> |
47 |
> -- |
48 |
> gentoo-hardened@g.o mailing list |
49 |
> |
50 |
|
51 |
|
52 |
-- |
53 |
gentoo-hardened@g.o mailing list |