Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by default; Desktop/audio RT developers, read this!

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Lennart Poettering wrote:

security is a matter of good design, not of "oh, look, he has become
evil, let's revoke his privileges" ad-hockery.

it should never be necessary to automatically revoke rights from users.
if i have to get rid of a misbehaving creature fast, "passwd -l villain"
in combination with "mv ~villain/.ssh /tmp" and a quick pkill fixes
things for me. and the very good part is that this decision is made by a
human, not by some imperial shitload of policy that caters to the needs
of some mythical desktop user.

your rtkit cannot protect against anything, you can just play policy
catch-up with evildoers forever. that's about the same level of security
that outgoing firewalls in windows provide - you depend on process names
and whatnot, and if i rename "Internet Explorer.exe" to "Windows
Update.exe", i'm free to do as i please (not quite, but you get the idea).
this is *not security*. this is theater. proper security sometimes
includes the wisdom that certain threats cannot be met without throwing
out the child with the bathwater. some daemon fiddling with rt privs at
runtime in my book qualifies as drowning the child first, then throwing
it out. maybe eating it afterwards, but i'm not sure.

_______________________________________________
Linux-audio-dev mailing list
Linux-audio-dev@lists.linuxaudio.org
http://lists.linuxaudio.org/mailman/listinfo/linux-audio-dev

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[LAD] [ANNOUNCE] Safe real-time on the desktop by default; D..., Lennart Poettering, (Fri Jun 19, 6:13 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 7:42 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Mon Jun 22, 3:56 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 1:32 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 12:58 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 3:50 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Sun Jun 21, 11:40 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 12:10 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 12:47 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Jörn Nettingsmeier, (Mon Jun 22, 9:36 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 9:43 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 6:18 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Sun Jun 21, 11:06 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 12:01 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Mon Jun 22, 3:58 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 1:14 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Wed Jun 24, 3:25 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Wed Jun 24, 5:46 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 12:06 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 3:27 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Sun Jun 21, 11:49 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Krzysztof Foltman, (Tue Jun 23, 11:19 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Dennis Schulmeister, (Tue Jun 23, 7:31 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Tue Jun 23, 4:09 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Sun Jun 21, 10:15 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 1:38 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Mon Jun 22, 6:15 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 6:24 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Mon Jun 22, 7:51 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 8:04 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Mon Jun 22, 9:18 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Mon Jun 22, 11:33 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 11:53 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Tue Jun 23, 12:33 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Krzysztof Foltman, (Mon Jun 22, 4:14 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Krzysztof Foltman, (Mon Jun 22, 4:58 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Mon Jun 22, 6:05 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 3:21 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 3:34 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 4:26 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Sun Jun 21, 11:41 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 12:21 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Jörn Nettingsmeier, (Mon Jun 22, 9:19 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 9:37 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 10:50 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Mon Jun 22, 10:07 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Dennis Schulmeister, (Mon Jun 22, 11:38 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Tue Jun 23, 12:00 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Dennis Schulmeister, (Tue Jun 23, 12:09 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Dennis Schulmeister, (Tue Jun 23, 1:49 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Tue Jun 23, 1:08 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 10:05 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Jörn Nettingsmeier, (Mon Jun 22, 9:47 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 10:02 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Jörn Nettingsmeier, (Tue Jun 23, 8:44 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Tue Jun 23, 4:54 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Tue Jun 23, 6:49 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Tue Jun 23, 8:14 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Fri Jun 26, 5:53 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Tue Jun 23, 10:19 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Wed Jun 24, 3:21 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Wed Jun 24, 3:23 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Wed Jun 24, 4:25 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Stephen Sinclair, (Wed Jun 24, 11:38 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Wed Jun 24, 12:24 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Fernando Lopez-Lezcano, (Fri Jun 26, 5:32 am)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Sun Jun 21, 11:53 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Mon Jun 22, 3:16 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Fri Jun 19, 8:04 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Sun Jun 21, 9:09 pm)
Re: [LAD] [ANNOUNCE] Safe real-time on the desktop by defaul..., Lennart Poettering, (Fri Jun 19, 6:46 pm)