Gentoo Archives: gentoo-hardened

From: Chris PeBenito <pebenito@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Keeping gentoo-hardened alive
Date: Wed, 13 Feb 2008 18:41:26
Message-Id: 1202928063.4777.9.camel@defiant.pebenito.net
In Reply to: Re: [gentoo-hardened] Keeping gentoo-hardened alive by atoth@atoth.sote.hu
1 On Wed, 2008-02-13 at 18:34 +0100, atoth@××××××××××.hu wrote:
2 > On Sze, Február 13, 2008 13:08, Geoff Kassel wrote:
3 > >
4 > > I like the idea of the SELinux per-application policies. I've never used
5 > > them
6 > > or SELinux, though, so I don't know how effective or simple they are to
7 > > use
8 > > IRL. Anyone else care to comment on this?
9 >
10 > Chris PeBenito is the person who probably have the most detailed knowledge
11 > of SELinux here. I think it's more complex to develop a policy for an
12 > application using SELinux, but a well designed framework provides
13 > guidance. Targeted mode offers a chance to create a balance between
14 > security and usability giving the chance for the everyday user to make use
15 > of the technique without having to spend time on the policy or facing with
16 > failing applications.
17
18 It depends on how far you want to go. Confinement on services
19 definitely is good, but for desktop applications can be problematic. In
20 Gentoo we only support the targeted policy on desktops as the
21 interactions between applications on the desktop vary so widely and
22 people do so many unexpected things that a firefox or evolution policy,
23 for example, ends up being far to restrictive for most people.
24
25 --
26 Chris PeBenito
27 <pebenito@g.o>
28 Developer,
29 Hardened Gentoo Linux
30
31 Public Key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xE6AF9243
32 Key fingerprint = B0E6 877A 883F A57A 8E6A CB00 BC8E E42D E6AF 9243

Attachments

File name MIME type
signature.asc application/pgp-signature