
天荣
31.05.2017
19:57:33
WannaCry wouldn't be able to spread inside a SELinux secured environment because it wouldn't have network access.
Even if you're root.

Michał
31.05.2017
19:58:39

Google

天荣
31.05.2017
19:58:51
No.
SELinux doesn't allow unknown applications to use the network.

Michał
31.05.2017
19:59:18
will have to check it, sounds nice

Ghazwan Aliesh
31.05.2017
19:59:56

Michał
31.05.2017
20:00:43
that way or another, you can make a cryptolocker which doesn't need network access (encrypt a key using a public key embedded in a ransomware, so the original key needs to be decrypted in a network service for example)

天荣
31.05.2017
20:01:25
The thing is WannaCry spread through the LAN using SMB exploits.
That would have been mitigated.
And I'm not completely sure SELinux would allow an unknown application to mass-encrypt files.
Certainly not delete the shadow copies (Which WannaCry did)
...Which would render it useless.

Michał
31.05.2017
20:03:22
I am pretty sure there are bugs in all applications. SELinux makes the attack vector narrow and things harder to pull off, plus low marketshare on desktops makes Linux not really an interesting target, but to think that such thing is impossible to do is foolish IMHO

天荣
31.05.2017
20:04:05
I never said impossible.

Google

天荣
31.05.2017
20:04:10
In fact I specified "mitigated"
Never said "block" but "mitigated"

Michał
31.05.2017
20:05:48
It's hard and that's a very good thing, but we need to keep in mind that the more popular Linux gets, the more probable is that attacks will start to appear - quite scary example was https://scarybeastsecurity.blogspot.com/2016/11/0day-exploit-compromising-linux-desktop.html

天荣
31.05.2017
20:06:40
Linux is incredibly popular.
Linux powers more machines in the world right now than all the Windows versions combined.
You can be sure of that.

Michał
31.05.2017
20:07:33
I know of shitty configuration on the vendor part
but still

天荣
31.05.2017
20:07:48
Those webcams weren't protected by SELinux now, were they? :P

norj
31.05.2017
20:08:30

Michał
31.05.2017
20:08:59

天荣
31.05.2017
20:09:19

Michał
31.05.2017
20:09:54
Meh... No.
So you're saying that if NSA would reaaally like to target Linux they would for sure be stopped by SELinux.

天荣
31.05.2017
20:10:05
No.
But it's highly unlikely.
SELinux is absurdly strict.

Michał
31.05.2017
20:10:44
the issue is, it takes one smallest mistake in SELinux
I don't know exactly how it works, does it protect kernelspace as well?

Google

天荣
31.05.2017
20:11:01
No. Not only a mistake in SELinux.
SELinux is a layer of many.
A well configured system has software and hardware firewall, user privilege separation, IDS/IPS...
And SELinux is only a layer more.
Break it all.

Michał
31.05.2017
20:12:10

天荣
31.05.2017
20:13:02
Don't forget a router is a hardware firewall on its own

norj
31.05.2017
20:13:03
"Also, a comparison of Ubuntu vs. Fedora — even when extended to the latest releases — reveals that Ubuntu is slipping behind Fedora "
Nice fedora

天荣
31.05.2017
20:13:05
So at least that

Michał
31.05.2017
20:13:58
I think I may learn something today - if I theoretically get to execute a malicious code as an user and miraclously overcome SELinux, what else is stopping me from doing bad things?
assuming an average desktop system, where applications are not executed as separate users

天荣
31.05.2017
20:14:41
Firewalls, IDS/IPS, as many layers as you wish.

Michał
31.05.2017
20:14:42
default Fedora installation
Firewall is not protecting me from doing curl to an http(s) server, I guess

天荣
31.05.2017
20:15:34
Depends on your goal too.

Michał
31.05.2017
20:15:39
I know I can do a lot, but I'm thinking default Fedora installation
I want to get ~/.ssh/id_rsa and post it to http://myserver.net using HTTP POST
I have run my code, overcome SELinux, so I can essentially cat ~/.ssh/id_rsa, what's stopping me from calling curl and uploading that?
...or someone listened to all these great advices on the internet to turn off SELinux :D

天荣
31.05.2017
20:32:26
What are you trying to prove?

Google

天荣
31.05.2017
20:32:40
That by turning off all possible protection you can do malicious stuff?

Michał
31.05.2017
20:49:10
That by turning off all possible protection you can do malicious stuff?
that by telling the people that SELinux is solving their problems magically they may put their guard down, then all it takes is to make a nice gnome theme with its own installer that asks for a root password, disables selinux and you're in. Of course, it requires some work on users part, but nevertheless, I think this myth of Linux being magically secure and virus-free is going to bite some newbie someday

天荣
31.05.2017
20:49:42
Because I didn't.

Michał
31.05.2017
20:51:19
+ those layers make things harder, but usually not impossible

天荣
31.05.2017
20:51:47
Yes.

(■_■¬)
31.05.2017
21:37:52

Admin
ERROR: S client not available

(■_■¬)
31.05.2017
21:41:42

天荣
31.05.2017
21:42:33
Right! They are not bad, they are ABSOLUTELY terrible.

(■_■¬)
31.05.2017
21:43:13
Taxation is theft
If the money is invested on war, massive destruction weapons and international terrorism aka democracy then yes, taxes are theft.

天荣
31.05.2017
21:43:19
It's been proven over and over in history that public infrastructure is ALWAYS more expensive than private business. You know why? Because taxes will always be there, even if they don't do their job OK. Private businesses go bankrupt if consumers don't vote them with their wallet.
These are facts.
You may not like facts.

(■_■¬)
31.05.2017
21:44:38

天荣
31.05.2017
21:45:42
Okay. Way to dismiss reality.
Your problem, not mine.

Google

神様の奴隷
31.05.2017
22:19:49
he's right tbh

LinuxIRC
31.05.2017
22:27:55
https://m.youtube.com/watch?v=d79vYwh4N1s#

Delta
01.06.2017
07:56:48
TIL in 1952, Wernher von Braun wrote a book called "Project Mars" which imagined that human colonists on Mars would be led by a person called "Elon" [Source]

Tobias?
01.06.2017
08:23:52
Where we pay more in taxes to DB after it has become a private company
And it shuts down more and more Services.

天荣
01.06.2017
08:26:08
That's what usually happens when the politicians are in bed with private entities :3

Tobias?
01.06.2017
08:26:49

pedro
01.06.2017
09:13:44
good morning, humans, furries and other entities

Michał
01.06.2017
09:13:54
hello

pedro
01.06.2017
09:13:55
hope all of you is good
:D
what a badass
?

Gwindor
01.06.2017
09:46:02
I arrived to Sochi. Got hotel room 404.
Funny part: I didn't find it initially. :D

Tobias?
01.06.2017
09:51:51