3 ms·
SELinux wasn't even invented for app sandboxing, even though e.g. Android uses it for that. There are LSMs designed for app sandboxing, like Canonical's AppArmo
by floatboth 7y ago
SELinux wasn't even invented for app sandboxing, even though e.g. Android uses it for that. There are LSMs designed for app sandboxing, like Canonical's AppArmor. SELinux (and MAC in general) comes from the NSA world of big government servers with complex policies about which actual human users can access which documents and so on.