LSS: Kernel security subsystem reports
LSS: Kernel security subsystem reports
Posted Sep 27, 2012 23:47 UTC (Thu) by spender (guest, #23067)In reply to: LSS: Kernel security subsystem reports by nix
Parent article: LSS: Kernel security subsystem reports
All these "new" SELinux ideas have me laughing and remembering back to times like in 2006 where a learning mode was considered harmful: http://securityblog.org/brindle/2006/04/02/top-down-vs-bo...
BTW it's funny that for all the "years of development" involved in SELinux policies, they haven't noticed that CAP_DAC_OVERRIDE is a superset of CAP_DAC_READ_SEARCH privilege and have been blindly creating policies and modifying code to add capability support that requires CAP_DAC_OVERRIDE (a full override of DAC) when only CAP_DAC_READ_SEARCH is needed.
It reminds me of the Schopenhauer quote: "All truth passes through three stages. First, it is ridiculed. Second, it is violently opposed. Third, it is accepted as being self-evident."
And again (as the pattern seems to be) upstream is only a decade behind ;)
-Brad
