4 ms·
I'm sorry but this is a horrible argument. Granular security is critical to having a system that can actually be locked down. Which is why SELinux support is
by jbjohns 15y ago
I'm sorry but this is a horrible argument. Granular security is critical to having a system that can actually be locked down. Which is why SELinux support is built into the kernel now.
- danudey 15y agoAnd from my experience, most admins turn it off immediately rather than rewriting security policies so that Apache can access data outside of /var/www/, etc. Sure you could modify the policy, but it's enough of a hassle that no one I know has ever done it. Restrictive security that just gets in people's way is terrible security. Just like forcing people to change their password every 14 days results in people using the same password repeatedly and incrementing a digit on the end (or writing the password down and sticking it on their monitor), creating overly complex rules means that people who absolutely must deal with these things (or who have the time) do so, and everyone else just turns it off and forgets it ever existed.
- __david__ 15y agoI'm glad I'm not the only one that hates SELinux. I find its setup to be super complicated yet all it ends up doing is stuff that I can do anyway with native unix permissions. As best I can tell it's a completely parallel world that is just there in case you mess up your normal permissions.
- jbjohns 15y agoYou admit that you don't understand SELinux so could it be that you hate it because you don't understand it? The fact is there are a lot of things that SELinux makes easier. In SELinux you have your services run in contexts and you can say what they can do (e.g. can listen on port 80 but not make outgoing connections, etc.). You no longer have this ridiculous need to run as one user (root) and switch to another. Unix security is so simple that, for my tastes, it's actually more complex to set up securely than SELinux. If you use a distro that supports it SELinux is drop dead simple anyway.
- lloeki 15y agoThe granularity actually can make it dangerous if it's an impediment to correctly designing such rights. Unix model has this advantage to be simple enough to accommodate most needs. A subtle misstep or two with ACLs can create a hard to notice path to escape, while since Unix rights are coarse, holes are generally quite coarse too.
- jbjohns 15y agoI would love for SELinux to be easier, but as far as I can tell it's the only game in town. I would never put anything internet facing that wasn't SELinux. Normal unix rights are simply not sufficient. Once you break into a program you can do everything the user that program is running under can do. Sure, you can create a new user for every bloody program/service you have but that means escalating privileges, etc. With SELinux I no longer have to worry about any switching-user nonsense. I can just give that service those specific rights. In that sense it is a lot simpler than the overly simplistic approach we've been using.