![]() |
|
#26
|
||||
|
||||
|
@ m00n,
Apparmor does work by pathname, that's correct. SELinux does not though. Quote:
Microsoft decided they don't want to give that choice to the users so they created their own security model, MIAC, and they're enforcing only that.
__________________
|
|
#27
|
|||
|
|||
|
Opens up a hole for attack how? I was under the impression that LSMs could only be changed or disabled on boot. And is this something purely theoretical, or has it been exploited in practice?
|
|
#28
|
||||
|
||||
|
Quote:
https://www.linux.com/learn/linux-tr...dule-what-isnt
__________________
|
|
#29
|
|||
|
|||
|
Quote:
Yep. I'd pick SELinux if I were using Linux. I prefer its method of protection over AppArmor. |
|
#30
|
||||
|
||||
|
You say that now =p but when you see a SELinux profile you'll change your mind.
__________________
|
|
#31
|
|||
|
|||
|
Quote:
No pain, no gain. ![]() |
|
#32
|
||||
|
||||
|
True. I would rather just use SELinux but it's a huge amount of pain for not a ton of gain =p
__________________
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|