Research
.
Skip Search Box

SELinux Mailing List

Re: threads

From: Stephen Smalley <sds_at_epoch.ncsc.mil>
Date: Wed, 21 Jan 2004 08:47:30 -0500


On Tue, 2004-01-20 at 20:11, Albert Cahalan wrote:
> This is not quite right. A server daemon using
> per-thread contexts is clearly within your trusted
> computing base, just as the kernel is. This can
> improve security over the obvious alternative of
> having the server run in a context that can do
> anything.

With such a model, you'll quickly end up with everything in your TCB and your system will be just as easily broken as before. Split your daemon into multiple processes running in different contexts instead. Improve security? No, just provide an illusion of it; no real separation is ensured.

> I was assuming you wouldn't hand out such
> privilige willy-nilly.

Once such a capability exists, people will use it for everything, and never even consider proper decomposition of their daemons.

> Isn't this the way LOMAC works?

Yes. But that doesn't mean it is a good idea.

-- 
Stephen Smalley <sds@epoch.ncsc.mil>
National Security Agency


--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.
Received on Wed 21 Jan 2004 - 08:47:38 EST
 

Date Posted: Jan 15, 2009 | Last Modified: Jan 15, 2009 | Last Reviewed: Jan 15, 2009

 
bottom

National Security Agency / Central Security Service