3 ms·
She is aware of this but has a bone to pick with the particular way that SE Linux secures the GUI: http://theinvisiblethings.blogspot.com/2011/04/linux-security
by long 12y ago
She is aware of this but has a bone to pick with the particular way that SE Linux secures the GUI: http://theinvisiblethings.blogspot.com/2011/04/linux-security-circus-on-gui-isolation.html?showComment=1303575708573#c8629263254767793603 http://theinvisiblethings.blogspot.com/2011/04/linux-securit...
I agree, though, that the style is overly aggressive.
- ris 12y agoI particularly disagree with her assertion that Xen is a more trustworthy place for security over the "big, bloated linux kernel". I would argue that the (perhaps smaller) Xen code has seen far less security scrutiny than the kernel and has a far less pronounced culture of security.
- zurn 12y agoLinux doesn't have a good culture of security. Local root bugs are dime a dozen. Security fixes in the kernel are not flagged as such. There's no systematic effort to stop the most common types of security bug (memory bugs in some driver ioctl handler). Linus doesn't have much patience for or interest in security improvements - look at http://article.gmane.org/gmane.linux.kernel/706950 http://article.gmane.org/gmane.linux.kernel/706950 - Etc etc.
- ris 12y agoBefore submitting, I debated whether to put a disclaimer line in - "not that the kernel has the worlds best security record", but I thought - nah nobody's going to use this as an opportunity to jump in & grind their "kernel security" axe. What a fool am I. I however think the relative silence around Xen security is far more of a worry. That was my point.