LWN.net Logo

BSD-style securelevel comes to Linux — again

BSD-style securelevel comes to Linux — again

Posted Sep 13, 2013 1:28 UTC (Fri) by dashesy (subscriber, #74652)
In reply to: BSD-style securelevel comes to Linux — again by giraffedata
Parent article: BSD-style securelevel comes to Linux — again

As long as there is anyway to own the device, you are the owner. If it requires soldering (or connecting BIOS to flash programmer) though, that does not count.


(Log in to post comments)

BSD-style securelevel comes to Linux — again

Posted Sep 13, 2013 2:08 UTC (Fri) by giraffedata (subscriber, #1954) [Link]

You lost me in the circular definition: anyone who is capable of owning is the owner. In normal English, anyone who actually does own is the owner. This appears to parse as, "the owner is a person who is capable of being the owner."

So who is the person identifed in the sysfs file? The person who owns or the person who is capable of owning (there could be many or none, I guess). Likewise, does the OWNER security mode mean programs have the privileges of owning or just are capable of getting them?

What it seems to come around to is that the highest security mode has to be called something other than OWNER in order for it to make any sense for a person to choose to run in a lower mode -- and that choice does make sense.

BSD-style securelevel comes to Linux — again

Posted Sep 13, 2013 17:19 UTC (Fri) by rsidd (subscriber, #2582) [Link]

I think you mean "pwn", not "own" :) In normal English, owners are not the same as superusers or sysadmins or vendors.

BSD-style securelevel comes to Linux — again

Posted Sep 13, 2013 17:25 UTC (Fri) by dashesy (subscriber, #74652) [Link]

Good point :)

Well for me I own a machine if I can do whatever I want with it (of course as long as it does not hurt others). Maybe I should have phrased it this way: I do not own a system if I cannot change /sys/owner name.

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds