4 ms·
I agree with your points about the Unix threat model being designed around protecting users from each other, but for completeness I'd like to point out that whi
by themulticaster 4y ago
I agree with your points about the Unix threat model being designed around protecting users from each other, but for completeness I'd like to point out that while modern Linux/BSD systems ship with Discretionary Access Control (DAC) by default, SELinux implements a Mandatory Access Control (MAC) system which is much more fine grained. SELinux is not limited to the traditional Unix security model.
Short simplified example highlighting DAC/MAC differences: DAC asks "is user Alice allowed to read Bob's files?" while MAC asks "is the SMTP server (subject user/role) process allowed to read private keys (object type) of the HTTP server (object user/role)?"
And if you're really motivated (read: want to have fun diagnosing unexpected file permission issues), you can associate files and processes with different security categories and levels (MCS/MLS), implementing horizontal and vertical separation. For example, "is this software update service allowed to read confidential files owned by the accounting database or keys used to encrypt classified information?"
There are other MAC systems besides SELinux as well.
- jnwatson 4y agoThe point of the article is that actually using a fine-grained MAC model is inconsistent with the way we actually use our tools. It requires deep understand of both the application and the model, which requires a lot of work.