3 ms·
The very first comment below the article (correctly) contradicts the author's claims about SELINUX sandbox. The author acknowledges the comment, and criticizes
by bm98 12y ago
The very first comment below the article (correctly) contradicts the author's claims about SELINUX sandbox. The author acknowledges the comment, and criticizes the SELINUX implementation, but does not dispute the fact that SELINUX sandbox ("sandbox -X xterm" in RHEL/CentOS/Fedora/SL) does in fact defeat the keystroke logger attack described in the article.
- reidrac 12y agoI would be nice if the article was amended to acknowledge the fact that a SELinux sandbox actually avoids "the problem". I'm being confused with the "you will likely need to install it first: yum install xorg-x11-apps"; which means you need extra privileges before implementing the attack "as normal user!". I guess the problem is not local access but a malicious app perhaps, but then it doesn't matter too much anyway because there are other ways of compromising the system.
- koios 12y agoThe yum install xorg-x11-apps bit is so you can use the xinput tool as a demonstration of the problem. Fedora doesn't have it by default apparently so you need to install it. A malicious app could just directly use the X protocol, no need to call this app, so unfortunately no additional privileges are needed.
- puzzlingcaptcha 12y agoApparently you don't need to execute it with elevated privileges so you can build it (or your own variant) statically on a different machine for all you care.
- xenophonf 12y ago"I guess the problem is not local access but a malicious app perhaps, but then it doesn't matter too much anyway because there are other ways of compromising the system." Well, that's the idea - protect a user from malicious apps running within their security context. Qubes does this by running apps within their own virtual machines.
- chris_wot 12y agoWhat did she mean by "The primary problem with SELinux sandbox is that it still relies on the big, buggy, bloated Linux kernel to enforce security." Genuinely curious.