Dailydave mailing list archives
RE: Media Excitement!
From: "Gilmore, Corey (DPC)" <Corey_Gilmore () dpc senate gov>
Date: Mon, 2 May 2005 10:47:17 -0400
On 4/27/05 byte_jump <bytejump () gmail com> wrote: On 4/26/05, robert () dyadsecurity com <robert () dyadsecurity com> wrote:
{big snip}
It means that after the compromise, the exploit is still limited inside the context of the web browser, normally morelimited than therole of the invoker of the web browser. Depends on thepolicy, but inmy policy it means that the web browser (and the exploit)can do whatit needs to do to function as a web browser. It can't spawn new programs, access the sound card, access files other thanit's cache,etc. Very fine grain controls, but I kept that example simple.But why not just give the web browser the access to API's and system calls that it needs? grsecurity and systrace can say, "You're only able to make the following system calls and listing the contents of ~/.gpg isn't one of them. You can only list the contents of the following directories..." and then rather than just let them list those directories, PaX/spp enforce appropriate behavior on those allowed system calls, memory mappings, etc.
HP is doing something similar to this, right now it's called Polaris. The demo I saw was a bit raw and it's only for the desktop, but it is a step in the right direction. You can't control it with a group policy yet either. [HP's] Abstract: Polaris is a package for Windows XP that demonstrates that we can do better at dealing with viruses than has been done so far. Polaris allows users to configure most applications so that they launch with only the rights they need to do the job the user wants done. This simple step, enforcing the Principle of Least Authority (POLA), gives so much protection from viruses that there is no need to pop up security dialog boxes or ask users to accept digital certificates. Further, there is little danger in launching email attachments, using macros in documents, or allowing scripting while browsing the web. Polaris demonstrates that we can build systems that are more secure, more functional, and easier to use. http://www.hpl.hp.com/techreports/2004/HPL-2004-221.html http://www.hpl.hp.com/techreports/2004/HPL-2004-221.pdf
I intend on digging a bit deeper with SELinux, but I have serious concerns with the scalability of it. When I'm hearing that I'll need to take _years_ to understand SELinux, there's too much complexity. When I hear that I need to change everything that I've learned about security in order to understand it, that's not a good sign. It's also not a good sign that policy analysis tools exist to tell me when I have what they say is an accurate policy. Why aren't the policies human-readable? How much do you trust those policy analysis tools? I'm pretty paranoid... Everything I'm hearing says "complex" and "error-prone" from an administrative standpoint. byte_jump _______________________________________________ Dailydave mailing list Dailydave () lists immunitysec com https://lists.immunitysec.com/mailman/listinfo/dailydave
_______________________________________________ Dailydave mailing list Dailydave () lists immunitysec com https://lists.immunitysec.com/mailman/listinfo/dailydave
Current thread:
- RE: Media Excitement!, (continued)
- RE: Media Excitement! Ben Nagy (Apr 21)
- Re: Media Excitement! Cody Hatch (Apr 22)
- Re: Media Excitement! robert (Apr 22)
- Re: Media Excitement! Cody Hatch (Apr 22)
- Re: Media Excitement! Roman Medina-Heigl Hernandez (Apr 22)
- Message not available
- RE: Media Excitement! Ron Gula (Apr 21)
- Re: Media Excitement! Brian (Apr 21)
- Re: Media Excitement! Brian Caswell (Apr 21)
