4 ms·
I agree that SELinux is largely unusable in the real-world (especially for custom apps). I've had better experience with path based MACs like tomoyo and apparmo
by _wldu 4y ago
I agree that SELinux is largely unusable in the real-world (especially for custom apps). I've had better experience with path based MACs like tomoyo and apparmor. Firejail is also great for end users who want to safely do online banking and surf the web at random on the same machine.
IMPO, this sort of isolation is the future of endpoint security. Linux has seccomp (to filter syscalls), landlock (to limit filesystem access), and other ways that devs can build these restrictions into their source code (no external MAC needed). I've lost count of the major and minor MACs that Linux offers now. OpenBSD has pledge and unveil that basically allow the same sort of thing.
I would not consider docker/podman as equivalent. They are great for bundling and running apps, but they are not doing mandatory access control. So be careful if you consider docker as a replacement for SELinux... it's not the same thing at all.
- 4khilles 4y agoOut of all the tools you mentioned, pledge and unveil are the most pleasant to use from a developer and operator's perspective. I'm hoping something something similar will arrive in Linux without it becoming xkcd 927.
- throwaway82652 4y agoThe capability to do something like that already exists in Linux, just nobody bothers to implement it at the application level because pledge and unveil are actually just more terrible hacks and are only really suitable for packages that are built into the system. In real syadmin-land, nobody wants to recompile applications just to change some security settings. Furthermore any of these things that are bolting more ACL or ACL-like restrictions onto Unix permissions are bound to eventually end up with the same problems as SELinux.