Walsh: Introducing the SELinux Sandbox
Walsh: Introducing the SELinux Sandbox
Posted May 27, 2009 1:59 UTC (Wed) by gdt (subscriber, #6284)In reply to: Walsh: Introducing the SELinux Sandbox by gdt
Parent article: Walsh: Introducing the SELinux Sandbox
Sorry, one other thing. The traditional Unix attitude to that ransom-demanding script is, "too bad, they've got root, game over". The point of SELinux is to say "you've got root, but you still don't get to win".
The focus with SELinux to date has to been to say "no" early enough so that no actual compromise of the machine by the root-obtaining exploit has succeeded.
What is starting to happen now is more interesting, which is to secure the privacy and integrity of data in a hostile environment.
