|
BobHoward posted:lollin at this this takes literally 10 seconds to troubleshoot
|
![]() |
|
![]()
|
# ? Jul 2, 2022 05:53 |
|
ahmeni posted:selinux is actually pretty easy once you spend the time it takes to sort out how it works
|
![]() |
|
turning off security stuff because its preventing you from doing something is like throwing away your smoke detector bc the battery is low and it keeps beeping. even me an idiot was able to learn enough about selinux to do stuff.
|
![]() |
|
no one uses selinux
|
![]() |
|
lots of people use it, and more people should e.g listing all correct and permissible behaviors for your average web app is very easy. listen on a named high number port. read files and directories tagged with a certain context. write files and directories with a different context. read/write /tmp. make outbound connections to a database. constraining login shells, for example, is a pain in the balls. but selinux policy is easy as poo poo for 99% of desktop and server applications
|
![]() |
|
pram posted:no one uses selinux
|
![]() |
|
Notorious b.s.d. posted:lots of people use it, and more people should nope
|
![]() |
|
it isnt set to enforcing, or even installed, on basically every cloud image in existence. if you are janitoring selinux on your desktop linux then lol
|
![]() |
|
pram posted:if you are janitoring selinux on your desktop linux then lol
|
![]() |
|
pram posted:it isnt set to enforcing, or even installed, on basically every cloud image in existence. if you are janitoring selinux on your desktop linux then lol this is more commentary on how dumb EC2 users are than evidence of SElinux use
|
![]() |
|
why yes amazon i would love a frankenstein linux image unsupported by any vendor with selinux turned off that sounds great
|
![]() |
|
pram posted:if you are janitoring linux on your desktop then lol
|
![]() |
|
ahmeni posted:selinux is actually pretty easy once you spend the time it takes to sort out how it works i'm sure there are people who actually believe that this http://pkgs.fedoraproject.org/cgit/rpms/selinux-policy.git/tree/policy-rawhide-base.patch is "pretty easy"
|
![]() |
|
Suspicious Dish posted:i'm sure there are people who actually believe that this http://pkgs.fedoraproject.org/cgit/rpms/selinux-policy.git/tree/policy-rawhide-base.patch writing policy for your app is a lot easier than writing all the policy needed to operate a linux distribution (when you complain C is hard, do you paste the entirety of glibc's source code into the argument?)
|
![]() |
|
selinux is just one of those shibboleths that nerds adopt to signal their cred. like functional programming and ham radios. utterly meaningless and pointless
|
![]() |
|
no one has ever thought selinux was cool security is never cool it is, however, necessary
|
![]() |
|
Notorious b.s.d. posted:writing policy for your app is a lot easier than writing all the policy needed to operate a linux distribution except your app's policy heavily depends on the distro policy. being able to debug your policy requires you to understand a lot about the rest of the system's policy.
|
![]() |
|
Suspicious Dish posted:except your app's policy heavily depends on the distro policy. being able to debug your policy requires you to understand a lot about the rest of the system's policy. of course. which is much easier than re-creating it from scratch. i can consume libc a lot easier than i could re-write libc
|
![]() |
|
also really nobody has working selinux except the redhat family. so really "knowing selinux" is "understanding how to use the stuff defined in that giant blob you pasted" i'd rather chew my own arm off than try and get selinux working on ubuntu
|
![]() |
|
lol at the people uniroically trash talking selinux and the one chosing ubuntu over fedora do you guys also login with root to your servers with password y/n
|
![]() |
|
Notorious b.s.d. posted:also really nobody has working selinux except the redhat family. so really "knowing selinux" is "understanding how to use the stuff defined in that giant blob you pasted" "knowing selinux" is "understanding enough to pass the rhce"
|
![]() |
|
pram posted:"knowing selinux" is "understanding enough to pass the rhce" the rhce is well-designed. it is not a coincidence that knowing enough to pass the rhce is also enough to implement selinux successfully in 99% of scenarios nobody expects that you're gonna go out and implement selinux from scratch on ubuntu. it's entirely reasonable to expect folks to write a few lines of selinux policy to get their web app du jour to work properly on centos in enforcing mode.
|
![]() |
|
SELinux is cool and good and if you don't understand it you are functionally retarded.
|
![]() |
|
dont sign your posts
|
![]() |
|
Celexi posted:lol at the people uniroically trash talking selinux and the one chosing ubuntu over fedora fedora didn't work at all. i guess that's secure.
|
![]() |
|
trying to fix the insecurities of linux users sounds like some sort of halting problem imo
|
![]() |
|
Breakfast All Day posted:trying to fix the insecurities of linux users sounds like some sort of halting problem imo
|
![]() |
|
Notorious b.s.d. posted:because centos has mandatory access control, and openbsd never will xnu implements mandatory access control based on FreeBSD, and has contributed changes back to FreeBSD
|
![]() |
|
selinux just seems unnecessary if the os is designed with security in mind from the ground up
|
![]() |
|
Maximum Leader posted:selinux just seems unnecessary if the os is designed with security in mind from the ground up yup, that's why the most secure OS in common use, iOS, doesn't need it
|
![]() |
|
Maximum Leader posted:selinux just seems unnecessary if the os is designed with security in mind from the ground up seatbelts just seem unnecessary if your driving style is designed with safety in mind from the ground up
|
![]() |
|
Soricidus posted:seatbelts just seem unnecessary if your driving style is designed with safety in mind from the ground up ![]()
|
![]() |
|
Cocoa Crispies posted:yup, that's why the most secure OS in common use, iOS, doesn't need it true words. apple design for security from the ground up, and there's no way they'd ever make a dumb mistake like that "goto fail" bug that hit linux users a year or so back
|
![]() |
|
Soricidus posted:apple lol Soricidus posted:apple design for security from the ground up hard to design for security from the ground up when you are the one creating the vector that will be exploited.
|
![]() |
|
didn't OSX recently get owned by LD_PRELOAD poo poo of the sort that people knew how to deal with back in the 80s
|
![]() |
|
Cocoa Crispies posted:yup, that's why the most secure OS in common use, iOS, doesn't need it ???? OSX and iOS have MAC its just that iOS enables it and it's administered by apple mostly its what keeps apps sandboxed iirc e: in fact the issue w/ selinux is the linux part w/ lots of one-eyed people leading around the blind
|
![]() |
|
Malcolm XML posted:???? OSX and iOS have MAC its just that iOS enables it and it's administered by apple mostly What is MAC? It's hard to google ios and mac for obv reasons.
|
![]() |
|
![]()
|
![]() |
|
akadajet posted:What is MAC? It's hard to google ios and mac for obv reasons. mandatory access control
|
![]() |
|
![]()
|
# ? Jul 2, 2022 05:53 |
|
weird. chrome keeps trying to fetch this with https and failing.
|
![]() |