3 ms·
This might be a bit pedantic, but “Linux” in the general sense doesn’t use the outdated security model you described. You’re basically comparing discretionary a
by mkipper 4y ago
This might be a bit pedantic, but “Linux” in the general sense doesn’t use the outdated security model you described. You’re basically comparing discretionary access control (e.g. user/group permissions) with mandatory access control (e.g. SELinux), both of which Linux happily supports…
…but the usage of MAC in Linux is so awkward that it might as well not exist, since the majority of distributions, packages and users ignore it completely to avoid all the headaches that come with it.
It’s tricky. It would be nice if the maintainers of big distributions/packages took MAC seriously and defaulted to restrictive SELinux policies or whatever, but history has shown this to be _very_ brittle and annoying for users. That’s why you see this stuff enabled in iOS and Android but not general Linux distributions — it’s much easier to lock things down with MAC when you’re developing a singular OS from scratch with apps that run in a sandboxed environment that’s isolated from the “system”. But if you’re maintaining something like python or pip, it’s basically impossible to do that.