Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Linux
  3. Why do we hate SELinux?

Why do we hate SELinux?

Scheduled Pinned Locked Moved Linux
linux
67 Posts 39 Posters 180 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M [email protected]

    This is not a troll post. I'm genuinely confused as to why SELinux gets so much of hate. I have to say, I feel that it's a fairly robust system. The times when I had issues with it, I created a custom policy in the relevant directory and things were fixed. Maybe a couple of modules here and there at the most. It took me about 15 minutes max to figure out what permissions were being blocked and copy the commands from. Red Hat's guide.

    So yeah, why do we hate SELinux?

    P This user is from outside of this forum
    P This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #51

    Nothing wrong with it

    It was built years ago by the NSA but I'm sure that by now any backdoors nwould have been found

    Having said that: it could use some rework to become more intuitive, especially with the error messages and how to resolve them

    1 Reply Last reply
    0
    • ? Guest

      Internet users like you are the worst.

      ? Offline
      ? Offline
      Guest
      wrote on last edited by
      #52

      Yep, we're right up there with lazy people who literally ask strangers to Google things for them and then sit back and wait for the response to be delivered to them personally. The worst.

      S daggermoon@lemmy.worldD 2 Replies Last reply
      0
      • ? Guest

        In the time it took you to type that comment here, you could have typed it in Google and gotten an immediate response

        W This user is from outside of this forum
        W This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #53

        Some people like to talk to each other. Like people who are people?

        ? 1 Reply Last reply
        0
        • W [email protected]

          Some people like to talk to each other. Like people who are people?

          ? Offline
          ? Offline
          Guest
          wrote on last edited by
          #54

          That's true. "define chair" is a great conversation starter.

          ? 1 Reply Last reply
          0
          • ? Guest

            Yep, we're right up there with lazy people who literally ask strangers to Google things for them and then sit back and wait for the response to be delivered to them personally. The worst.

            S This user is from outside of this forum
            S This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #55

            This is an online DISCUSSION

            Stfu

            ? 1 Reply Last reply
            0
            • ? Guest

              In the time it took you to type that comment here, you could have typed it in Google and gotten an immediate response

              daggermoon@lemmy.worldD This user is from outside of this forum
              daggermoon@lemmy.worldD This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #56

              Was trying to start a discussion, my bad.

              1 Reply Last reply
              0
              • ? Guest

                Yep, we're right up there with lazy people who literally ask strangers to Google things for them and then sit back and wait for the response to be delivered to them personally. The worst.

                daggermoon@lemmy.worldD This user is from outside of this forum
                daggermoon@lemmy.worldD This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #57

                If they brought up SELinux I'd assume they had no need to Google it.

                ? 1 Reply Last reply
                0
                • M [email protected]

                  This is not a troll post. I'm genuinely confused as to why SELinux gets so much of hate. I have to say, I feel that it's a fairly robust system. The times when I had issues with it, I created a custom policy in the relevant directory and things were fixed. Maybe a couple of modules here and there at the most. It took me about 15 minutes max to figure out what permissions were being blocked and copy the commands from. Red Hat's guide.

                  So yeah, why do we hate SELinux?

                  F This user is from outside of this forum
                  F This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #58

                  It's more work to get things to work. You have to be more explicit as a dev.

                  Personally I really like it, and wish there was more support for MLS features it has in Userland

                  1 Reply Last reply
                  0
                  • daggermoon@lemmy.worldD [email protected]

                    If they brought up SELinux I'd assume they had no need to Google it.

                    ? Offline
                    ? Offline
                    Guest
                    wrote on last edited by
                    #59

                    I would agree until they asked what it is

                    1 Reply Last reply
                    0
                    • S [email protected]

                      This is an online DISCUSSION

                      Stfu

                      ? Offline
                      ? Offline
                      Guest
                      wrote on last edited by
                      #60

                      Exactly. You tell em! This is a discussion! It's not a place to ask for definitions.

                      S 1 Reply Last reply
                      0
                      • ? Guest

                        Exactly. You tell em! This is a discussion! It's not a place to ask for definitions.

                        S This user is from outside of this forum
                        S This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #61

                        U mad tho

                        ? 1 Reply Last reply
                        0
                        • H [email protected]

                          I don't hate it, but as a PC/phone user it's security features are almost never helpful and always cause issues so I just have it disabled.

                          S This user is from outside of this forum
                          S This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #62

                          I never have any issues with it in fedora

                          1 Reply Last reply
                          0
                          • S [email protected]

                            U mad tho

                            ? Offline
                            ? Offline
                            Guest
                            wrote on last edited by
                            #63

                            No U mad

                            1 Reply Last reply
                            0
                            • daggermoon@lemmy.worldD [email protected]

                              I don't hate it. What's SELinux?

                              G This user is from outside of this forum
                              G This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #64

                              SELinux is an access control system for Linux. Traditionally Linux uses Dynamic Access Control (DAC) which basically means the person who creates a file can determine who can access that file. Thats pretty fine for day to day use but there are some problems with this model in terms of security. One I can think of is that it's more vulnerable to privilege escalation (a hacker getting access to a higher level account like admin through a lower level account) because it puts the onus on the user to define who can access the file. SELinux was invented by our good friends at the NSA to remedy these kinds of problems. It's an example of Mandatory Access Control. It works on top of DAC by creating policies that work to prevent things like privilage escalation. It's a lot more comprehensive than DAC

                              1 Reply Last reply
                              0
                              • noxypaws@pawb.socialN [email protected]

                                I'd love to develop a muscle memory for working with it, but nowhere I've worked uses it at all. But from memory it really wasn't that complicated, and the errors it spat out into system logs basically told you exactly what command to run to get past that particular violation.

                                I don't hate it at all. Just, never seen it used anywhere.

                                I This user is from outside of this forum
                                I This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #65

                                All the linux stacks I was involved with over the years always had SELinux disabled as part of the base config. I can't think of a single server it was enabled on.

                                1 Reply Last reply
                                0
                                • M [email protected]

                                  This is not a troll post. I'm genuinely confused as to why SELinux gets so much of hate. I have to say, I feel that it's a fairly robust system. The times when I had issues with it, I created a custom policy in the relevant directory and things were fixed. Maybe a couple of modules here and there at the most. It took me about 15 minutes max to figure out what permissions were being blocked and copy the commands from. Red Hat's guide.

                                  So yeah, why do we hate SELinux?

                                  pseudospock@lemmy.dbzer0.comP This user is from outside of this forum
                                  pseudospock@lemmy.dbzer0.comP This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #66

                                  Because in even 'permissive' mode, it blocks some fairly routine things.

                                  1 Reply Last reply
                                  0
                                  • ? Guest

                                    That's true. "define chair" is a great conversation starter.

                                    ? Offline
                                    ? Offline
                                    Guest
                                    wrote on last edited by
                                    #67

                                    An elevated platform that is raised on one side (forming a "back") designed with the intent of sitting... No "back" = stool

                                    1 Reply Last reply
                                    0
                                    • System shared this topic
                                    Reply
                                    • Reply as topic
                                    Log in to reply
                                    • Oldest to Newest
                                    • Newest to Oldest
                                    • Most Votes


                                    • Login

                                    • Login or register to search.
                                    • First post
                                      Last post
                                    0
                                    • Categories
                                    • Recent
                                    • Tags
                                    • Popular
                                    • World
                                    • Users
                                    • Groups