Civilizing SELinux
Posted Nov 26, 2004 4:58 UTC (Fri) by
bluefoxicy (guest, #25366)
In reply to:
Civilizing SELinux by spender
Parent article:
Civilizing SELinux
Want to bet that if someone were to send a mail to FD and Bugtraq demanding that Fedora fix their information leaking glibc that they've refused to fix for months now, it would be fixed?
Brad, do us all a favor. You're pretty smart, you can map out these things and make a comprehensive report on what's wrong, why it's wrong, and why it needs to be fixed, right? Go do it.
I'd really love Linux and hell my favorite distribution to carry the "security torch," and really want to see PaX and GR get the credit they deserve. SELinux and RSBAC are good too though; but I personally despise the hype SE gets, not because anything else is better or worse, but because a lot of people get just that-- hype.
When you focus on ONE solution, you come up with a crowd that thinks it's a magic bullet that will mitigate everything else, sometimes even including patches. We went through the same kind of thing with firewalls. Norton Personal Firewall, Zone Alarm, Black Ice, all things people thought "would stop [crackers]" all by themselves. I wasn't around to see if they did the same thing with Antivirus software, though I imagine this "magic program that removes [cracker] programs will fix everything!!!" Most people still blame 100% of their problems on viruses.
You need a diverse range of solutions: PaX, MAC, GRSec's kernel enhancements, SSP, firewalling, augment ClamAV with heuristics, use application proxy firewalls and firefox/thunderbird plug-ins to scan for malware in web pages and e-mail, etc.
I'm not sure what my exact point is WRT this topic, but there's stuff relavent here I'm sure, since I kind of went all over the place.
(
Log in to post comments)