Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #244731

Re: Security

From Nicholas Geovanis <nickgeovanis@gmail.com>
Newsgroups linux.debian.user
Subject Re: Security
Date 2022-01-28 17:30 +0100
Message-ID <DKCil-7fX-11@gated-at.bofh.it> (permalink)
References <DJAiB-7jg-3@gated-at.bofh.it> <DJCkq-hG-9@gated-at.bofh.it> <DJVn4-4Zi-3@gated-at.bofh.it> <DKqqR-84C-1@gated-at.bofh.it> <DKBcC-6Eh-15@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

On Fri, Jan 28, 2022, 9:17 AM Vincent Lefevre <vincent@vinc17.net> wrote:

> On 2022-01-27 21:44:07 -0600, Nicholas Geovanis wrote:
> > On Wed, Jan 26, 2022, 12:39 PM Andrei POPESCU <andreimpopescu@gmail.com>
> > wrote:
> >
> > > I'll use the opportunity to draw attention to DSA-5059-1, see e.g. this
> > > article for details:
> > >
> > >
> > >
> https://arstechnica.com/information-technology/2022/01/a-bug-lurking-for-12-years-gives-attackers-root-on-every-major-linux-distro/
> > >
> > > And please don't bother to reply with "there are no other users on this
> > > system I should worry about", the bad guys could still find ways to get
> > > in, e.g. via a compromised browser, regardless if you are behind a
> > > firewall or not[1].
>
> Running the browser in firejail should be sufficient as the profile
> should disable pkexec, e.g.
>

Vincent's point is the right one I think. We need to deploy security "in
depth". Every single setuid executable should be SHIPPED protected, just
pick your style of protection.

SElinux should be shipped enabled like Redhat does. Think it's too hard to
administer? Then ship it with multiple models implemented in multiple rule
sets like Redhat does. Then you can choose your style of mandatory access
control with a mouse click at installation.

$ firejail --profile=firefox ls
> Reading profile /etc/firejail/firefox.profile
> [...]
> Error: execute permission denied for /usr/bin/pkexec
> Error: no suitable pkexec executable found
>
> > Servers don't have browsers installed on them, for exactly this reason.
>
> Servers shouldn't have pkexec installed in the first place, anyway.
>
> --
> Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
> 100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
> Work: CR INRIA - computer arithmetic / AriC project (LIP, ENS-Lyon)
>
>

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 21:10 +0100
  Re: Security Andy Smith <andy@strugglers.net> - 2022-01-25 21:50 +0100
    Re: Security Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2022-01-25 22:00 +0100
      Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-26 16:40 +0100
  Re: Security Nate Bargmann <n0nb@n0nb.us> - 2022-01-25 23:20 +0100
    Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-26 19:40 +0100
      Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 04:50 +0100
        Re: Security Dan Ritter <dsr@randomstring.org> - 2022-01-28 14:20 +0100
          Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 17:20 +0100
            Re: Security Dan Ritter <dsr@randomstring.org> - 2022-01-28 19:00 +0100
        Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-01-28 16:20 +0100
          Re: Security Nicholas Geovanis <nickgeovanis@gmail.com> - 2022-01-28 17:30 +0100
          Re: Security Richard Hector <richard@walnut.gen.nz> - 2022-01-30 13:40 +0100
            Re: Security Reco <recoverym4n@enotuniq.net> - 2022-01-30 14:20 +0100
              Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-30 14:40 +0100
                Re: Security Reco <recoverym4n@enotuniq.net> - 2022-01-30 17:50 +0100
                Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-02-04 09:50 +0100
                Re: Security Reco <recoverym4n@enotuniq.net> - 2022-02-04 10:20 +0100
                Re: Security <tomas@tuxteam.de> - 2022-02-04 10:20 +0100
            Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-02-01 12:30 +0100
              Re: Security Richard Hector <richard@walnut.gen.nz> - 2022-02-02 02:00 +0100
                Re: Security Vincent Lefevre <vincent@vinc17.net> - 2022-02-02 15:10 +0100
        Re: Security Andrei POPESCU <andreimpopescu@gmail.com> - 2022-01-28 17:30 +0100

csiph-web