top | item 43777559

(no title)

jmainguy | 10 months ago

If your root, you can just turn off selinux

discuss

order

fipar|10 months ago

Not without a reboot though, and while I haven’t done that, it should be possible to protect selinux ‘s config itself with a policy, requiring boot loader access to bypass, at which point you’re dealing with a different risk level.

I’ll agree that Linux security is quite limited and primitive if compared with, say, a mainframe, but it can be made less bad with a reasonable amount of effort.

saagarjha|10 months ago

What would the mainframe be running that avoids this problem?