I've always considered the kernel securelevels
feature of FreeBSD to be the most significant
difference between, e.g., debian and FreeBSD
for a host like a web server.
By going into a higher securelevel, it's possible
to make files truly immutable. That is, no user,
not even root, can modify files that have the
immutable flag set. And the immutable flag can't
be unset. That means you can set up the server
such that trojaning its system programs (like login
and ls) becomes impossible.
Linux has some features aimed at providing this
level of security, but I've been waiting for
them to come together in a usable way for a while.
Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds