Dailydave mailing list archives

RE: Media Excitement!


From: "Gilmore, Corey (DPC)" <Corey_Gilmore () dpc senate gov>
Date: Mon, 2 May 2005 10:47:17 -0400

On 4/27/05 byte_jump <bytejump () gmail com> wrote:

On 4/26/05, robert () dyadsecurity com <robert () dyadsecurity com> wrote:


{big snip}

It means that after the compromise, the exploit is still limited 
inside the context of the web browser, normally more 
limited than the 
role of the invoker of the web browser.  Depends on the 
policy, but in 
my policy it means that the web browser (and the exploit) 
can do what 
it needs to do to function as a web browser.  It can't spawn new 
programs, access the sound card, access files other than 
it's cache, 
etc.  Very fine grain controls, but I kept that example simple.

But why not just give the web browser the access to API's and 
system calls that it needs? grsecurity and systrace can say, 
"You're only able to make the following system calls and 
listing the contents of ~/.gpg isn't one of them. You can 
only list the contents of the following directories..." and 
then rather than just let them list those directories, 
PaX/spp enforce appropriate behavior on those allowed system 
calls, memory mappings, etc.

HP is doing something similar to this, right now it's called Polaris.
The demo I saw was a bit raw and it's only for the desktop, but it is a
step in the right direction.  You can't control it with a group policy
yet either.

[HP's] Abstract: Polaris is a package for Windows XP that demonstrates
that we can do better at dealing with viruses than has been done so far.
Polaris allows users to configure most applications so that they launch
with only the rights they need to do the job the user wants done. This
simple step, enforcing the Principle of Least Authority (POLA), gives so
much protection from viruses that there is no need to pop up security
dialog boxes or ask users to accept digital certificates. Further, there
is little danger in launching email attachments, using macros in
documents, or allowing scripting while browsing the web. Polaris
demonstrates that we can build systems that are more secure, more
functional, and easier to use.

http://www.hpl.hp.com/techreports/2004/HPL-2004-221.html
http://www.hpl.hp.com/techreports/2004/HPL-2004-221.pdf





I intend on digging a bit deeper with SELinux, but I have 
serious concerns with the scalability of it. When I'm hearing 
that I'll need to take _years_ to understand SELinux, there's 
too much complexity.
When I hear that I need to change everything that I've 
learned about security in order to understand it, that's not 
a good sign.

It's also not a good sign that policy analysis tools exist to 
tell me when I have what they say is an accurate policy. Why 
aren't the policies human-readable? How much do you trust 
those policy analysis tools? I'm pretty paranoid...

Everything I'm hearing says "complex" and "error-prone" from 
an administrative standpoint.

byte_jump
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
https://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: