Slashdot Mirror


HP-LX 1.0 Secure Linux

kengreenebaum writes: "Webtechniques has a short but interesting article on HP's approach to a secure but expensive LINUX distro. Basically they started with RedHat 7.1 and added compartments; an extension to the age-old chroot jail concept where the processes representing major services run. Kernel extensions allow HP (or the administrator) to specify which compartments can access which kernel resources including individual files, network stacks, and each other. HP has Technical Product Brief as well as other material online. Interesting to compare HP's approach to that of the NSA's Secure Linux projects. These concepts sound like a solid way to prevent buffer overflow type security holes in individual services from compromising the entire machine. At $3000 HP-LX is too expensive for many to experiment with but the NSA's code seems to be more readily available. Anybody have experience with these distributions or with similar approaches to Linux security?"

7 of 182 comments (clear)

  1. The first post is always the most insightful. by Anonymous Coward · · Score: -1, Offtopic

    That's why I share it with you.

  2. F1rst pozt! by Anonymous Coward · · Score: -1, Offtopic

    Fuck you other slowpokes!

  3. My server's already secure by Anonymous Coward · · Score: -1, Offtopic

    $3000 nothing, I did it for $4 and a pack of gum. That's right, I have Rodrigo, an 8 year old street urchin, in a cabinet next to my server. A little bit of training and some stale saltines every day, and I've got the perfect Heuristic firewall.

  4. S237ISAFB : FKA : FP by Anonymous Coward · · Score: -1, Offtopic

    Abreviations of my favourite trolls, can you guess what they are?

  5. Re:Eh? How can they get away with selling that? by Anonymous Coward · · Score: -1, Offtopic

    Hahaha, you dumbass. Do you really think the FSF could take on HP? Large corperations can violate the GPL all they want and no one can do shit about it.

  6. Re:WARNING JAVASCRIPT ATTACK AFTER THE "b&" by Anonymous Coward · · Score: -1, Offtopic

    Dude, I'm looking at the source of the comments page in OmniWeb 4.1b1. I'm seeing b&. I'm not seeing .

    (Unless of course the admins already removed the script =D)

  7. ADVERT : GOATSE.CX! by Anonymous Coward · · Score: -1, Offtopic

    NOTE : DO NOT MODERATE THIS POST, DOING SO WILL RESULT IN PENAMENT BANNING FROM SLASHDOT AND/OR LEGAL DAMAGES TOTALING UP TO AND INCLUDING €50,000!


    Slash dot is glad to annonce this cool new site that we discovered, it is really cool and intresting and you will almost certainly enjoy it!


    The url is http://www.goatse.cx/

    END OF SLASH AD