Slashdot Mirror


FreeBSD Gets a New Security Officer

ve2asm writes "As sent to the freebsd-announce mailing list, Kris Kennaway is resigning as Security Officer. The core team has approved Jacques Vidrine as the new security officer.

7 of 15 comments (clear)

  1. OT: Missing html tag by c.r.o.c.o · · Score: 1

    Is it just me, or did CmdrTaco forget a tag? After this article, everything below it is italic. The quoted paragraphs, the moderator comments, everything.

    However, the story right above this one is displaying normaly.

    BTW, don't moderate me as off topic, I'm just asking a question that would not fit anywhere else but here.

  2. BlatantWhoring: A good "secure your BSD" link. by WasterDave · · Score: 2

    http://draenor.org/securebsd/secure.txt

    A clear simple guide to securing FreeBSD, including use of secure levels.

    Two links off the homepage, so it's blatant whoring.

    Dave

    --
    I write a blog now, you should be afraid.
    1. Re:BlatantWhoring: A good "secure your BSD" link. by __past__ · · Score: 2, Interesting
      BTW, am I the only one who thinks that securelevels stink?

      IMHO it would be a better idea to be able to select the features securelevels imply individually. That way, one could still use the securelevel settings in /etc/rc.conf by just making /etc/rc setting a group of individual "securesettings".

      I mean, just because I happen to like rewriting my firewall rules doesn't mean I want anybody to be able to write to kmem, or to remove noschg!
    2. Re:BlatantWhoring: A good "secure your BSD" link. by Anonymous Coward · · Score: 1, Interesting

      You want something like Linux's capability bits.

      Of course, to actually use them in a non-trivial way you pretty much HAVE to roll your own distro from scratch.

    3. Re:BlatantWhoring: A good "secure your BSD" link. by cperciva · · Score: 3, Interesting

      am I the only one who thinks that securelevels stink?

      Nope. Every time the topic came up in freebsd-security, Kris used to lead the "securelevels are broken, don't use them" charge.

      To be fair, they could be a useful security feature (although a more fine-grained control would of course be superior), but you'd have to do all sorts of stuff in order for that to happen. They are still quite useful as an anti-foot-shooting device, however.

    4. Re:BlatantWhoring: A good "secure your BSD" link. by kkenn · · Score: 1

      Or FreeBSD's capability bits, available in 5.0.

  3. hmm by nomadic · · Score: 5, Funny

    As sent to the freebsd-announce mailing list, Kris Kennaway is resigning as Security Officer.

    I didn't know any actually managed to make it long enough to resign. Aren't they usually killed a few minutes after they beam down to a planet, or blown up by an exploding console?