Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You admit that you don't understand SELinux so could it be that you hate it because you don't understand it?

The fact is there are a lot of things that SELinux makes easier. In SELinux you have your services run in contexts and you can say what they can do (e.g. can listen on port 80 but not make outgoing connections, etc.). You no longer have this ridiculous need to run as one user (root) and switch to another.

Unix security is so simple that, for my tastes, it's actually more complex to set up securely than SELinux. If you use a distro that supports it SELinux is drop dead simple anyway.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: