Posted Jul 11, 2008 18:51 UTC (Fri) by nix (subscriber, #2304)
[Link]
Well, yeah, but part of the point of SELinux was, I thought, that root
could be confined. (Not that this is terribly useful, because there are
too many ways that root can mess up the machine. To hear PaXTeam et al
talk, everyone's running with a confined root so that DoS attacks and
holes only exploitable by root are significant. I find it rather unlikely
that *anyone* who cares about security is running under the assumption
that confined root really is secure, exactly because of the enormous
number of such 'attacks'. But I don't have any numbers and may be wrong.)