Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 05 Oct 2020 22:36:14 -0400
From: Steve Grubb <sgrubb@...hat.com>
To: oss-security@...ts.openwall.com
Cc: Solar Designer <solar@...nwall.com>
Subject: Re: major changes if gnu/linux dominates the desktop and/or mobile market?

On Monday, October 5, 2020 4:48:20 PM EDT Solar Designer wrote:
> On the desktop, major Linux distributions (and by the way *BSDs and
> Solaris are not very different in this respect, I think) when used as
> single-user desktop systems lack security isolation between applications
> of the user.  (And also between the user and root, due to the typical
> recommended use of sudo from the user account.)

I will skip the whole discussion on access control. However to prove security 
requires going through a Common Criteria certification. The biggest issue is 
that the desktoptop uses dbus instantiation which does not have the auid of 
the requesting process. Meaning audit cannot work.

The fix was kdus. That was rejected. But the issue remains. There cannot be a 
secure desktop without auditing. And no one is really pushing for a desktop 
certification, therefore no one is pushing to fix audit desktop problems.

-Steve


Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.