4 ms·
I read this article a few years ago and thoroughly enjoyed it, but I've had trouble solving Default Permit in practice. Does anyone know of a free software ope
by gpcz 12y ago
I read this article a few years ago and thoroughly enjoyed it, but I've had trouble solving Default Permit in practice. Does anyone know of a free software operating system that white-lists its software (say by having the white-list be tied to the package manager) without having to do a lot of tinkering/configuring? I know you can do it with certain Linux add-ons that provide mandatory access control like SELinux and grsecurity, but it always seems like they introduce problems that you then have to troubleshoot for hours before your system is usable again. Bonus points for if this distro uses ASLR, W^X, and other countermeasures to avoid violating the security policy through code injection.
- codyb 12y agoI don't know of any viable desktop solutions for this issue, but it seems to be how iOS works. Unless you jail break your phone you cannot download or install anything not on the app store (where everything goes through a review boardI believe). And I haven't heard much about iOS viruses really. Maybe for the jail broken ones? A quick google search turns up this malware [0] which only works through USB. So the system does seem to be working pretty well all in all. Reducing the attack vectors from everything to direct hardware connections only is a pretty big accomplishment I'd think. [0] - http://www.computerworld.com/article/2843764/security0/wirelurker-ios-virus-usb-malware-itbwcw.html http://www.computerworld.com/article/2843764/security0/wirel...
- big_youth 12y agoYes, you are correct. All ios apps must be code signed by Apple which is pretty stringent in it's reviews. This is why you won’t find any apps in the app store attempting to spawn /bin/bash or mimic its functionality. I believe apple is now requiring all osx apps on the app store be code signed as well.
- MichaelGG 12y agoNot free, by Windows can do this quite well. You whitelist the system and program files dir, and audit acls. Works fine. It's called Software Restriction Policy. There's also AppLocker, but MS limits that to certain SKUs because they forgot it's not the 90s anymore. Actually, HyperV has SRP, and it's free as in beer. Seems like a simple path based system would work on Linux, as long as there aren't debuggers and such available to users.
- robryk 12y agoIt seems to me that mounting everything user-writable as noexec should be very similar to what you want. That said, it will not prevent a user from executing arbitrary code, but will make it much more complicated than "download this bunary and click it". (It's still possible to use a debugger to load something into an existing process; IIRC you can LD_PRELOAD a library from a noexec location, etc.)