3 ms·
Some interesting insights on Grsecurity's approach by OpenBSD's Nick Holland in the comments section: https://www.digitalocean.com/community/tutorials/an-intro
by hiphopyo 11y ago
Some interesting insights on Grsecurity's approach by OpenBSD's Nick Holland in the comments section:
https://www.digitalocean.com/community/tutorials/an-introduction-to-selinux-on-centos-7-part-1-basic-concepts https://www.digitalocean.com/community/tutorials/an-introduc...
- j_s 11y agoLink directly to the comment: https://www.digitalocean.com/community/tutorials/an-introduction-to-selinux-on-centos-7-part-1-basic-concepts?comment=17853 https://www.digitalocean.com/community/tutorials/an-introduc... And here is the referenced email with a bit of context: http://osdir.com/ml/general/2014-02/msg44493.html http://osdir.com/ml/general/2014-02/msg44493.html
- aidenn0 11y agoSubstitute "Untrusted user" for "possibly buggy server code" and you will see why Grsecurity's approach can have value in single-user systems.
- _yy 11y agoHe's actually talking about the SELinux/"RBAC in general" approach. His only criticism of Grsecurity is that it's not in the mainline and therefore not as effective as it could be.