From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1750779AbWDXM4r (ORCPT ); Mon, 24 Apr 2006 08:56:47 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1750774AbWDXM4q (ORCPT ); Mon, 24 Apr 2006 08:56:46 -0400 Received: from e31.co.us.ibm.com ([32.97.110.149]:24989 "EHLO e31.co.us.ibm.com") by vger.kernel.org with ESMTP id S1750776AbWDXM4p (ORCPT ); Mon, 24 Apr 2006 08:56:45 -0400 Date: Mon, 24 Apr 2006 07:56:41 -0500 From: "Serge E. Hallyn" To: Alan Cox Cc: Lars Marowsky-Bree , Valdis.Kletnieks@vt.edu, Ken Brush , linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: Time to remove LSM (was Re: [RESEND][RFC][PATCH 2/7] implementation of LSM hooks) Message-ID: <20060424125641.GD9311@sergelap.austin.ibm.com> References: <4445484F.1050006@novell.com> <200604182301.k3IN1qh6015356@turing-police.cc.vt.edu> <4446D378.8050406@novell.com> <200604201527.k3KFRNUC009815@turing-police.cc.vt.edu> <200604211951.k3LJp3Sn014917@turing-police.cc.vt.edu> <200604230945.k3N9jZDW020024@turing-police.cc.vt.edu> <20060424082424.GH440@marowsky-bree.de> <1145882551.29648.23.camel@localhost.localdomain> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1145882551.29648.23.camel@localhost.localdomain> User-Agent: Mutt/1.5.11 Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org Quoting Alan Cox (alan@lxorguk.ukuu.org.uk): > On Llu, 2006-04-24 at 10:24 +0200, Lars Marowsky-Bree wrote: > > On 2006-04-23T05:45:34, Valdis.Kletnieks@vt.edu wrote: > > > > > > AppArmor are not likely to put careful thought into the policies that > > > > they use? > > > They're not likely to put careful thought into it, *AND* that saying things > > > like "AppArmor is so *simple* to configure" only makes things worse - this > > > encourages unqualified people to create broken policy configurations. > > > > That is about the dumbest argument I've heard so far, sorry. > > Its the conclusion of most security experts I know that broken security > is worse than no security at all. By the way, this is predicated on the assumption that the broken security will cause the user to expose more data. However in many cases these days, that is sadly not the case. Amazon will store my cc data regardless whether they are running selinux, apparmor, or nothing. -serge