Re: MAC policies and shared hosting



Unfortunately the MAC framework just doesn't seem to get
as much attention as I'd like. I think the problem was
that the TrustedBSD project seemed very 'closed' in that the
site was quite rarely updated and it was difficult to get news
on developments. It seemed, for a long time, that nobody was
interested in it.

Well, I am loving it, really.

It'd be nice to see a ton of tutorials, papers and documentation
for it. I personally would write quite a bit on it if I could get started
but unfortunately my 'expertise' begins and ends at the web server
example in the handbook.

I think also the MAC framework is perceived as being too difficult
to use and too detached from FreeBSD itself. Hopefully the latter
will improve when BSM is integrated with the system and the
former is entirely subjective anyway.

Well, as you increase security there is a tradeoff. But I'm trying to come up with a reasonable balance between security and convenience. Deploying it has important consequences on operations like, for example, a make world. You must be aware of it.

I'm trying to do it in the Apple way: make it simple enough to be usable, but make it strong enough :)




Borja.

_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: What server hardening are you doing these days?
    ... I have to say that this is one of the more attention getting ... I've been reading most of the guides that have flown ... having an impact on production. ... >that anybody who is touching Win2K3, claims interest in security, yet hasn't ...
    (Focus-Microsoft)
  • Re: Shame on Microsoft
    ... "it's something that has been missed for a decade in security ... inspections of the OS done by both Microsoft and hackers trying to exploit ... > Just in case the point Jonathan was making slipped past your attention... ... >>> Microsoft to have such serious holes in their software. ...
    (microsoft.public.security)
  • Re: Computer virus???
    ... We initially received amazing attention and service from 24-7 Security. ... About 3 months into our 1 year contract, ... We are now spending money to have a different company come in to fix ...
    (alt.security.alarms)
  • Re: Full analysis of the .ida "Code Red" worm.
    ... > all the infrastructure, because, in theory the compromised servers ... This calls to question the attention of systems administrators to ... The days of selective application of security patches are ...
    (Bugtraq)