Walsh: Introducing the SELinux Sandbox
Walsh: Introducing the SELinux Sandbox
Posted May 27, 2009 22:29 UTC (Wed) by foom (subscriber, #14868)In reply to: Walsh: Introducing the SELinux Sandbox by PaXTeam
Parent article: Walsh: Introducing the SELinux Sandbox
running may have some exploitable vulnerabilities, so any access restrictions are completely
meaningless.
In the real world, people do run multiuser linux machines.
Security is not black and white, there is such a thing as more secure and harder to break into.
This is one more link in the chain, designed to help secure single-user machines. Now, not only
do you need to be running a vulnerable JPEG rendering library to have your files stolen, you
*also* need to be running a kernel which is exploitable in the limited attack surface presented to
the JPEG decoding process.
Surely it's a good thing to attempt to limit the attack surface?
> where did you say your most valuable personal box can be accessed again ;)?
Here:
http://www.coker.com.au/selinux/play.html
(okay, it's not mine :)
