3 ms·
Seriously? I'd recommend doing some more research before making that claim. Your example in a later comment speaks to the area of Privilege Separation, discus
by drewpc 9y ago
Seriously? I'd recommend doing some more research before making that claim. Your example in a later comment speaks to the area of Privilege Separation, discussed (and implemented) ad nauseam throughout nearly every application that is maintained by the OpenBSD project.
http://niels.xtdnet.nl/papers/privsep.pdf http://niels.xtdnet.nl/papers/privsep.pdf
http://www.citi.umich.edu/u/provos/ssh/privsep.html http://www.citi.umich.edu/u/provos/ssh/privsep.html
https://www.openbsd.org/papers/ven05-deraadt/index.html https://www.openbsd.org/papers/ven05-deraadt/index.html
https://www.openbsd.org/innovations.html https://www.openbsd.org/innovations.html
- hapless 9y agoPrivilege separation is also a nice feature, but it is not the same as MAC. I would have much greater confidence in an OpenBSD project that included lomac or capsicum.