Похожие чаты

What vulnerabilities and/or threats can SELinux and AppArmor mitigate in

layman term?
Are them really necessary for Desktop? And if so, is Arch distro which lacks official support for them considered as insecure?

29 ответов

31 просмотр

In layman's terms, they are mitigating a lot of Chair-Keyboard interface issues, like inserting that USB drive you found on the parking lot and opening the pdf that was inside for example

Kiavash-Yk Автор вопроса
Ludovic 'Archivist' Lagouardette
In layman's terms, they are mitigating a lot of Ch...

So, they seems useless and just protect the system from high level of stupidity.

Kiavash Yk
So, they seems useless and just protect the system...

If you think you are not stupid and don't need them, you are precisely the kind of person that needs them

AppArmor lets you define permissions for each program and denies that program access to anything you haven't allowed it to do. I write my own AppArmor profiles so that I can run some required proprietary software without having to worry about it doing weird things to my OS. Thanks to AppArmor it can only do what I let it do. It can write to ~/Downloads, but not to ~/Documents. It can't read info about my hardware. Even if I were careless enough to start it as root, it still wouldn't have any root privileges except the ones I defined in the profile.

Kiavash Yk
According to your example.

Have you ever run a command that pipes curl to bash or an installer that depends on such a command?

Kiavash-Yk Автор вопроса
Ludovic 'Archivist' Lagouardette
Have you ever run a command that pipes curl to bas...

The first one is a no, the second one could be a popular, well-known AUR.

Ender
AppArmor lets you define permissions for each prog...

That is really important Allowing any program to read your ssh and gpg keys, documents, photos, etc is terrible

Kiavash Yk
So, they seems useless and just protect the system...

They protect you from programs that do more than they need to. They also allow you to follow the principle of least privilege. Say you run tcpdump. It need to be root. But it doesn't need all the power that root has. With AppArmor you can run it as root, but it will only have a few special permission, not the full set of root capabilities.

Kiavash-Yk Автор вопроса
Ender
AppArmor lets you define permissions for each prog...

Is writing its profiles difficult? Would you please share a sample?

Kiavash Yk
Is writing its profiles difficult? Would you pleas...

See my profile for skypeforlinux at https://gitlab.com/alexconst.sh/apparmor-profiles/-/blob/dev/usr.bin.skypeforlinux for example.

Kiavash Yk
Is writing its profiles difficult? Would you pleas...

If you're on Debian or Ubuntu, install the apparmor-profiles package and look around in /etc/apparmor.d

Kiavash-Yk Автор вопроса
Ender
If you're on Debian or Ubuntu, install the apparmo...

I'm on fedora 34 right now, was wondering about switch to an arch-based distro [endeavourOS exactly], and concerned about keeping it as secure as fedora.

Ludovic 'Archivist' Lagouardette
This is pretty good, allow me to steal that 😉

Make sure to read comments at the top of the file. Also see the end of README.md, there's a suggestion to further mitigate Xorg vulnerabilities.

Kiavash-Yk Автор вопроса
Kiavash Yk
Thank you

btw I mainly restrict filesystem access. AppArmor can do much more. You can restrict mounting filesystems to specific mount points or fs types. You can restrict dbus access. Or make the program use TCP only. Or deny network access entirely. It's very flexible.

Kiavash-Yk Автор вопроса
Martin Rys
Why not Arch?

I expect you say so:)

Mihai
Why not Ubuntu?

Why not Windows... Oh wait

Mihai
Why not Ubuntu?

*breathes in heavily*

Martin Rys
*breathes in heavily*

Imagine going to south africa to sell your soul to Amazon

Похожие вопросы

Обсуждают сегодня

Господа, а что сейчас вообще с рынком труда на делфи происходит? Какова ситуация?
Rꙮman Yankꙮvsky
29
А вообще, что может смущать в самой Julia - бы сказал, что нет единого стандартного подхода по многим моментам, поэтому многое выглядит как "хаки" и произвол. Короче говоря, с...
Viktor G.
2
@Benzenoid can you tell me the easiest, and safest way to bu.y HEX now?
Živa Žena
20
This is a question from my wife who make a fortune with memes 😂😂 About the Migration and Tokens: 1. How will the old tokens be migrated to the new $LGCYX network? What is th...
🍿 °anton°
2
30500 за редактор? )
Владимир
47
а через ESC-код ?
Alexey Kulakov
29
What is the Dex situation? Agora team started with the Pnetwork for their dex which helped them both with integration. It’s completed but as you can see from the Pnetwork ann...
Ben
1
Гайс, вопрос для разносторонее развитых: читаю стрим с юарта, нада выделять с него фреймы с определенной структурой, если ли чо готовое, или долбаться с ринг буффером? нада у...
Vitaly
9
Anyone knows where there are some instructions or discort about failed bridge transactions ?
Jochem
21
@lozuk how do I get my phex copies of my ehex from a atomic wallet, to move to my rabby?
Justfrontin 👀
11
Карта сайта