5 ms·
>> You can't just add them later, on top of the legacy Mac OS SELinux managed it, what's fundamentally stopping MacOS?
by CraigJPerry 2y ago
>> You can't just add them later, on top of the legacy Mac OS
SELinux managed it, what's fundamentally stopping MacOS?
- result2vino 2y agoCan your grandma use SELinux? Delusional.
- mu53 2y agoSELinux is for distro and package maintainers to use. Not end users.
- lmz 2y agoAnd yet for a large number of years any RHEL/CentOS SELinux issues with third party software were answered with "disable SELinux".
- homebrewer 2y agoSame for Windows' UAC in the Vista era, which doesn't make it bad technology or place the fault on Microsoft. The world is full of terrible development practices, the answer shouldn't be "just disable your security mechanisms".
- lmz 2y agoSo you agree that end users do use it and are often incapable of getting the things they want to work with it?
- snakeyjake 2y agoA large number of years up to and including "this year, right now, like, yesterday".
- johnnyjeans 2y agoMy Grandma doesn't have a need for backwards compatibility or the million other things that stop Apple from just making a new operating system. Normal people's use cases for their computer is light file management, light document and productivity workflows and everything else is done in the browser. Hell, most of the document processing and productivity crap is in the browser these days too.
- lapcat 2y agoIn other words, your grandma could use an iPad rather than a Mac.
- homebrewer 2y ago> delusional That's rather self critical of you, even if deserved. My grandma also can't write software, or really do anything advanced, no should she be able to. SELinux, just like any other security and/or containerization technology, is supposed to be used by developers, sysadmins, distribution maintainers. Not by end users. Is the macos sandbox the odd one out? I'm not familiar with it, but find it very hard to believe that "my grandma" is its target audience.
- cyberax 2y agoIf she has an Android phone, she's already using it.
- lapcat 2y agoThere's a [dead] reply that you may not see, but frankly I kind of agree with it: "Can your grandma use SELinux? Delusional." https://news.ycombinator.com/item?id=42087188 https://news.ycombinator.com/item?id=42087188
- nolist_policy 2y agoAndroid uses SELinux.
- lapcat 2y agoSo? You can't compare Android to macOS. Compare Android to iOS, which had many more limitations built-in from the start than macOS. Incidentally, this is why iPad has never become the desktop replacement everyone claimed it would be. The hardware is plenty powerful, but it's always been very limited by the software. The greater freedom and capabilities of macOS is a huge advantage for desktop-class functionality.
- hollerith 2y agoI think I disagree. If iOS or Android added robust support for external monitors, external keyboards and pointing devices, I'd probably switch to it to get the increased resistance against attacks. If I could continue to run Emacs, e.g., in a VM like WSL2 or Crostini, I'd probably switch right away. If not, it would take me a year or 2 to transition to a replacement before I switch (and, no, that replacement would not need to be able to run software written in Emacs Lisp: I'd be happy to replace, rewrite or walk away from any functionality I currently get from code written in Emacs Lisp).
- nextos 2y agoI use Linux, I would not switch to Android, but I agree the Linux userland should take sandboxing much more seriously. Things like Firejail show it can be done without much friction for the user. The current model, where executables can access any user file or resource, needs to go. We haven't learned anything from e.g. compromised pip packages that stole ssh keys.
- lmz 2y agoUsability. And/or good taste.
- CraigJPerry 2y agoUsability is apple’s thing. My AirPods just work, every Bluetooth headset before just annoyed. Why can’t they achieve usability in this space? To be honest, redhat’s solution is pretty darned usable - in the context of an enterprise Linux box(1). it helps that they built that database of policy profiles but even creating my own policy is pretty straightforward (3 commands + whatever it takes to make my app exercise all its code paths) (1) apples context is obviously different
- acdha 2y agoSELinux can be part of the solution but it doesn’t solve the problem. The median Linux system is far behind the median Mac because while SELinux exists you still have to craft fine-grained policies and deal with all of the exceptions needed to have the system still be usable. This is more a function of budget than anything else.
- CraigJPerry 2y ago>> SELinux can be part of the solution but it doesn’t solve the problem Hold on that’s changing the goalposts a bit here. SELinux doesn’t solve this problem on RHEL boxes by virtue of just existing. It is the tool that Redhat uses to solve the problem. And they have solved the problem by using this tool. To the point that for years now, by default, RH boxes are installed in enforcing mode. >> The median Linux system is far behind the median Mac I’m not really interested in the median because for better or worse, Redhat is the most serious game in town for SELinux. Comparing Mac to RHEL, there’s only one place where Mac is ahead and that is a default Mac install at least on Apple silicon will have an immutable root. Redhat has irons in the fire here (rpm ostree can infuturue unlock a user friendly immutable root). Of course you can do immutable root today (and immutable usr and even epehemeral var if you want), but I’m not going to argue those are user friendly. An experienced sysadmin will take a minute to flip over between immutable root file systems during an upgrade process. >> This is more a function of budget than anything else. Agreed, but the Apple chequebook looks plenty beefy.
- acdha 2y ago> And they have solved the problem by using this tool. To the point that for years now, by default, RH boxes are installed in enforcing mode. They’ve shipped it, yes. It doesn’t count as solved until all of the apps are running with policies which actually block attacks like this, just as having a fire extinguisher on the shelf doesn’t mean your fire is guaranteed to be out. > Comparing Mac to RHEL, there’s only one place where Mac is ahead and that is a default Mac install at least on Apple silicon will have an immutable root. Also they have far more common use of sandboxing for applications (including the harder bits about selective permissions for apps), code signing, memory protection, pervasive use of HSM and robust layered storage encryption, etc. – all out of the box, whereas even in the much easier case of servers you’re looking at many hours of skilled labor to configure an equivalent. My point about budgets is that this is just a lot of work. Apple’s not perfect but a lot of people have a mental model from the 2000s which is no longer true.
- nyrikki 2y agoComplete different set of tradeoffs. This is one of those situations where there is no good option, just the least worse option. SE had mostly servers, depends on package vendors being altruistic, and people mostly just disabled it when it caused problems. That is a very different set of assumptions and challenges than what Apple faces.
- CraigJPerry 2y agoAgreed, I’m not suggesting selinux itself is the solution for Apple. I’m just saying faced with the same problem, and accepting that they have different usability constraints on them (sysadmins vs potentially novice computer users), another group found a solution. Why can’t Apple - they have the money to buy the engineering resource to bottom this out.
- throw0101a 2y ago> SELinux managed it Not when you have SELINUX=disabled (rather than SELINUX=enforcing), which is what I've seen in most environments. Personally I've had better experiences with AppArmour.
- CraigJPerry 2y ago>> Not when you have SELINUX=disabled Yeah of course, but by default Redhat will install in enforcing mode. This is taking a horse to water, the drinking is left to the horse.