SELinux vs. OpenBSD’s Default Security

KernelTrap offers a summary of a lengthy debate on OpenBSD’s -misc mailing list comparing the security features built into OpenBSD versus the security offered by the Linux kernel’s SELinux feature. The main arguments presented against SELinux centered around its complexity and the difficulty of defining a secure policy. “The first thing people usually do with SELinux is turn it off”, suggests the article, noting that the ease with which it can be turned off is another security shortcoming. By contrast, OpenBSD offers numerous security features that are always enabled with minimal overhead, including propolice stack protection, random library mappings, proactive privilege separation, W^X, and systrace.

61 Comments

  1. 2007-09-26 7:53 pm
    • 2007-09-26 8:05 pm
      • 2007-09-26 9:07 pm
        • 2007-09-27 4:55 am
          • 2007-09-27 6:02 am
      • 2007-09-26 10:04 pm
    • 2007-09-27 1:04 am
      • 2007-09-27 1:42 am
      • 2007-09-27 4:50 am
    • 2007-09-27 1:48 am
  2. 2007-09-26 8:00 pm
    • 2007-09-26 9:15 pm
      • 2007-09-26 11:57 pm
        • 2007-09-27 6:01 am
          • 2007-09-27 6:45 am
  3. 2007-09-26 8:19 pm
    • 2007-09-26 8:36 pm
    • 2007-09-27 12:47 pm
      • 2007-09-27 2:10 pm
  4. 2007-09-26 8:29 pm
  5. 2007-09-26 8:38 pm
  6. 2007-09-26 8:42 pm
    • 2007-09-26 10:00 pm
    • 2007-09-27 2:37 pm
  7. 2007-09-26 8:51 pm
    • 2007-09-26 9:10 pm
      • 2007-09-26 9:17 pm
      • 2007-09-26 10:24 pm
      • 2007-09-27 2:10 am
  8. 2007-09-26 9:25 pm
    • 2007-09-26 10:32 pm
    • 2007-09-26 10:34 pm
    • 2007-09-26 11:21 pm
    • 2007-09-27 12:10 am
      • 2007-09-27 12:21 am
        • 2007-09-27 4:37 am
  9. 2007-09-27 3:32 am
    • 2007-09-27 4:46 am
  10. 2007-09-27 3:33 am
  11. 2007-09-27 5:56 am
    • 2007-09-27 6:10 am
    • 2007-09-27 7:57 am
      • 2007-09-27 8:50 am
        • 2007-09-27 9:50 am
          • 2007-09-27 9:57 am
  12. 2007-09-27 9:43 am
    • 2007-09-27 9:54 am
      • 2007-09-27 10:18 am
        • 2007-09-27 10:40 am
          • 2007-09-27 11:00 am
  13. 2007-09-27 7:32 pm
  14. 2007-09-27 7:51 pm
    • 2007-09-27 8:00 pm
      • 2007-09-27 8:09 pm
        • 2007-09-27 10:50 pm
          • 2007-09-28 2:11 am
          • 2007-09-28 8:07 am
          • 2007-09-28 2:42 pm
        • 2007-09-28 2:10 am
    • 2007-09-28 2:09 am
      • 2007-09-28 11:47 am