how to secure my computer

This is a discussion on how to secure my computer within the Linux Security forums, part of the System Security and Security Related category; "Mikhail Zotov" <muxaul@lenta.ru> (06-04-17 20:46:11): > > Yes, it doesn'...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #31 (permalink)  
Old 04-18-2006
Ertugrul Soeylemez
 
Posts: n/a
Default Re: how to secure my computer

"Mikhail Zotov" <muxaul@lenta.ru> (06-04-17 20:46:11):

> > Yes, it doesn't only provide security, but even beauty. I like it
> > hiding processes not owned by the user requesting the process list.

>
> Hm. Is this really PaX that allows one to hide user processes? IIRC,
> one can disable PaX but still have this feature present by enabling
> appropriate settings in "Filesystem Protections" (Allow special group,
> GID for special group).


No, that's not a PaX feature, but a grsecurity feature. Remember that
PaX is packaged with grsecurity, but otherwise completely unrelated. So
yes, you can disable PaX and still get this feature.


> > In my opinion, that would be security by obscurity, so I wouldn't
> > use it for security purposes. It's just beautiful, because it makes
> > my 'ps' output much smaller.

>
> I agree with the point. IMHO, the feature also "improves" privacy on
> multi-user machines since users who don't belong to the "special
> group" can see only their own processes.


Well, there are other means of detecting 'well known' running processes,
e.g. '/tmp/' or '/var/run/', or even side channel attacks.


Regards.
Reply With Quote
  #32 (permalink)  
Old 04-18-2006
Mikhail Zotov
 
Posts: n/a
Default Re: how to secure my computer

Ertugrul Soeylemez wrote:
> "Mikhail Zotov" <muxaul@lenta.ru> (06-04-17 20:46:11):
> > Ertugrul Soeylemez wrote:
> > > In my opinion, that would be security by obscurity, so I wouldn't
> > > use it for security purposes. It's just beautiful, because it makes
> > > my 'ps' output much smaller.

> >
> > I agree with the point. IMHO, the feature also "improves" privacy on
> > multi-user machines since users who don't belong to the "special
> > group" can see only their own processes.

>
> Well, there are other means of detecting 'well known' running processes,
> e.g. '/tmp/' or '/var/run/', or even side channel attacks.


Yep, you are right again. :-)

--
Mikhail

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 08:58 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0