Wed Apr 12 20:59:41 UTC 2017
Valeri Galtsev <galtsev at kicp.uchicago.edu>

On Wed, April 12, 2017 2:39 pm, Mauricio Tavares wrote:
Continuing in the same spirit. Way back SELinux (before it made it into
main stream kernel) had a competitor. LIDS. De-ciphers as Linux Intrusion
Detection System (but name is confusing). Creature of Purdue University
Computer science department. Basically LISD was a kernel patch that upon
end of boot sequence demotes root account to privileges of user nobody.
This makes system impregnable on the fly (but real pain to administer -
any change can only be done as: shut down, change, boot). I was so
impressed, I still remember about it. Never came to using it though. If it
did, it might give big pain to NSA and friends. But SELinux won, and LIDS
never made it into main stream kernel - to my regret. As far as SELinux is
concerned, several people still think that several (how many?) thousands
of extra code in the kernel may bring more harm than do good. Anyway, the
last IMHO is where "tastes differ".


