[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <alpine.DEB.0.9999.0709301609150.8382@asgard>
Date: Sun, 30 Sep 2007 16:24:00 -0700 (PDT)
From: david@...g.hm
To: Andi Kleen <ak@...e.de>
cc: casey@...aufler-ca.com, Andrew Morton <akpm@...ux-foundation.org>,
torvalds@...ux-foundation.org,
linux-security-module@...r.kernel.org,
linux-kernel@...r.kernel.org, James Morris <jmorris@...ei.org>,
Paul Moore <paul.moore@...com>
Subject: Re: [PATCH] Version 3 (2.6.23-rc8) Smack: Simplified Mandatory Access
Control Kernel
On Sun, 30 Sep 2007, Andi Kleen wrote:
>> The authentication issues are very real, but a separate issue.
>
> First rule of network security: don't trust the network.
This I agree with
> Without authentication it's completely useless. I don't understand
> how you can disregard that as "separate issue". Security is only
> secure if you plugged all applicable holes; without that it's useless
> and you might as well not bother.
but this is so silly that I have to object.
saying that any security short of perfect security is worthless and we
shouldn't bother is wrong, and needs to be countered every time it's
said.
as ted pointed out in response to your other comments, it very much
depends on where the trust boundry is. so from the point of view of
absolute security you are wrong.
but even more then that, the vast majority of the time absolute security
isn't what matters, relative security is what matters (the model of "I
don't have to outrun the bear, I only have to outrun you") and in these
envrionments things that are less then absolute can still be very useful.
how useful they are depends on a lot of details, and in the case of the
network security being discussed it sure sounds like it's pretty close to
useless if you can't trust the network and the other machines on it, but
that is seperate from the mentality that "anything less then perfect
security is worthless and shouldn't be bothered with" which is what I'm
objecting to.
David Lang
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists