Skip to main content

Do We Really Need Layered Security For Single User Computers?


I have a subscription to user support in the fedora users mail list. I came across a thread about SElinux. Selinux is the mandatory access control security layer implemented in fedora and Red Hat Enterprise linux. In Ubuntu (also in OpenSuse) they implement MAC through Apparmor.

From:  Andrew R Paterson <andy.paterson@ntlworld.com>
File system permissions require at least basic knowledge and
> administration.  Most of the people I installed Linux for don't even
> know what they're good for.

> If your computer is single-user anyway, why does it need a security
> subsystem?


> *eyeroll*
Having watched this debate I find I must add my own 10c
I have spent over 30 years working on unix systems starting with xenix, bsd 
and ending up with linux .....
We survived quite happily using the well known DAC methods of standard UNIX.
(UGO - RWX - setuid etc).
Then I worked on some military systems (high security stuff) and started to use 
SOLARIS CMW (Compartentalised Mode Workstation) and DEC MLS (Multi-Level-
Security).
These both use the same (probably not as up to date) MAC security via 
labelling as (I guess) selinux.
I can truthfully say I loved UNIX in all its forms until coming across CMW & 
MLS and now SELINUX - then basically - I wanted OUT!.
They are horrendous; if you start to use labelling in earnest - absolutely 
suicidal!!! - unless you have a real motive - ie you work for the security 
services or a bank or something  and have a massive amount of time to devote.
Why do the selinux guys have to force MAC onto all linux users - even 
hobbyists?
Its getting like some kind of religion!

May I add that MAC is implemented differently in Ubuntu. Only *some* critical processes are protected. Layered security helps to protect our computer from zero-day attacks. It makes it less susceptible to system-wide malware attacks.
--
Use my PGP key if you want to encrypt your replies/messages to me. You are invited to also send me your PGP keys so we can communicate in private.




--
Use my PGP key if you want to encrypt your replies/messages to me. You are invited to also send me your PGP keys so we can communicate in private.

Comments

Popular posts from this blog

Appindicator In Natty Ubuntu 11.04

Previously ranted about the blind alley Ubuntu 11.04 seemed to be leading us when it comes to some applications not being ready yet for the dropping of system tray.  What I should have done is press on. There are posts about editing a white list with a recommended GUI tool to help us out here , here and here . Like everything in Linux, there's a configuration file for it, if you can find it and if you have the inclination to go ninja. If not then there's dconf-editor. Download dconf-tools from Software Center. Navigate to desktop>unity>panel. Add your application in the white list. Then close the window. No save button. mmm. So far I have added Shutter, Dropbox and Keepassx in the white list.                Before...  After.

Evolution Mail on GNOME 3.26

There's a slight change in the user interface. A To Do column now appears to the rightmost after the GNOME 3.26 update. Also there's a noticeable stability increase, what with goa-daemon stopping its RAM usage creep. I don't have to kill it every couple of hours.

New Converge ICT Plan Max with Sky Now

I pulled the trigger on Converge Max plan 400Mbps with Sky channels. I went to their sales office and asked for the upgrade. No charge at all and they didn't ask me to return the old modem. It looks like they will pull it when they install the new modem.e     It came with a black box for the TV. The configuration is easy but it took me 3 days to figure out the Wired connection. It should be fine except I have to jiggle it in the config (GUI). Turn 802.1x  on and off to finally connect.  Here's the speed for the Wired connection: