, 2005-06-21
Expand all |
Post comment
Interview with Marcus Ranum
2005-06-22
some guy in Central PA (1 replies)
some guy in Central PA (1 replies)
Interview with Marcus Ranum
2005-06-22
Anonymous (1 replies)
Anonymous (1 replies)
Re: Interview with Marcus Ranum
2005-06-22
Marcus Ranum (2 replies)
Marcus Ranum (2 replies)
Re: Re: Interview with Marcus Ranum
2005-06-22
Anonymous (1 replies)
Anonymous (1 replies)
Interview with Marcus Ranum
2005-06-22
Tails (2 replies)
Tails (2 replies)
Re: Interview with Marcus Ranum
2005-06-22
Marcus Ranum (7 replies)
Marcus Ranum (7 replies)
What A Total Jackass
2005-06-22
Anonymous (1 replies)
Anonymous (1 replies)
Interview with Marcus Ranum
2005-06-24
Anonymous (2 replies)
Anonymous (2 replies)

_that_ having been said, selinux has the ability to place some restrictions on network access on a per-user+per-program basis.
it is therefore my belief that a heavily modified version of "fwbuilder" could output selinux policies on a per-desktop and per-server basis that could lock down linux desktop and linux server machines as envisaged - without the need for an expensive Cisco ACL router.
... of course, if an individual machine is root-kitted or LKM-compromised (something that selinux cannot help you with because selinux is implemented in the kernel and a kernel exploit means Game Over) then its rules get ignored...
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/334/32045#32045