lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <242a0a8f0603271404w49ea63aei9e01a82bc1a1f8ab@mail.gmail.com>
Date: Mon Mar 27 23:04:10 2006
From: eaton.lists at gmail.com (Brian Eaton)
Subject: 4 Questions: Latest IE vulnerability,
	Firefox vs IE security, User vs Admin risk profile,
	and browsers coded in 100% Managed Verifiable code

On 3/27/06, Pavel Kankovsky <peak@...o.troja.mff.cuni.cz> wrote:
> On Mon, 27 Mar 2006, Brian Eaton wrote:
>
> > I wasn't sure if Windows actually supported mandatory access controls,
> > so I poked around on Microsoft's web site a bit.  Yes, Windows
> > supports MAC.
>
> MS Windows does not support MAC. Its future version (i.e. Vista) might
> support some half-baked (*) pseudo-MAC.

Thanks for the info.  I'm not a windows expert by any mean, just going
by what I read on their web site. ;-)

> > In his original note, Dinis raised a good point: even a restricted
> > browser has access to all kinds of sensitive personal information,
> > such as passwords to web sites.  MAC would not prevent an exploit from
> > stealing that kind of data.
>
> Nonsense. MAC was invented by soldiers and spooks to protect
> confidentiality. (The use of MAC to protect integrity is, in fact, an
> afterthought.)
>
> Properly implemented and configured MAC can prevent the leakage of
> confidential (i.e. sensitive personal) information to (unauthorized) web
> sites.

You lost me here.  How would you design a MAC policy that lets firefox
remember my password for a web site, but doesn't let arbitrary code
running via a buffer overflow get at that same password?

Regards,
Brian

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ