Skip to content

Comment on Detaining David Mirandaparent

Comments

Obviously not having knowledge as to how the NSA uses it on their systems, but out of the box and in every realworld configuration I've come across it has little to no impact on what the root user can do.

Have you ever worked on a Mandatory Access Control computer system of any kind? They are extremely inconvenient, and thus rare to find outside classified environments. The engineering effort to write and maintain a functional set of SELinux policies is a large budget item. But the NSA did not engineer and release SELinux because it doesn't work.

Mostly due to so many programs "requiring" if you have selinux enabled, disable it prior to installation and use.

That and its not always trivial to setup policies to make things work (or to "know" that you haven't missed something) I see a lot of selinux set to just not enforce at all.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.