Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
TheDong
on April 18, 2015
|
parent
|
context
|
favorite
| on:
Suicide Linux (2011)
Just make it work at the kernel syscall level. Maybe make it so you can have policies where syscalls can only affect some directories.
Maybe we should call it "selinux"
CHY872
on April 18, 2015
[–]
Of course, but that has a reputation as being hard to set up into a configuration that doesn't get in the way.
TheDong
on April 18, 2015
|
parent
[–]
Ah, yes, and not allowing deleting files or changing permissions and so on would give you security without ever getting in the way. Silly me.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search:
Maybe we should call it "selinux"