lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Sun, 11 Nov 2007 15:02:05 +0800 From: "Rogelio M. Serrano Jr." <rogelio@...global.net> To: undisclosed-recipients:; Cc: Linux Kernel Mailing List <linux-kernel@...r.kernel.org>, LSM ML <linux-security-module@...r.kernel.org>, apparmor-dev <apparmor-dev@...ge.novell.com> Subject: Re: AppArmor Security Goal Dr. David Alan Gilbert wrote: > > > Allowing a user to tweak (under constraints) their settings might allow > them to do something like create two mozilla profiles which are isolated > from each other, so that the profile they use for general web surfing > is isolated from the one they use for online banking. > > Doesnt this allow the user to shoot their own foot? The exact thing mandatory access control are supposed to prevent? > Dave > -- Democracy is about two wolves and a sheep deciding what to eat for dinner. View attachment "rogelio.vcf" of type "text/x-vcard" (333 bytes) Download attachment "signature.asc" of type "application/pgp-signature" (253 bytes)
Powered by blists - more mailing lists