• 0 Posts
  • 24 Comments
Joined 6 months ago
cake
Cake day: June 10th, 2025

help-circle





  • What I am saying is that it looks significantly more daunting then it truly is, once you understand the basic concept of it (which I’m positing is actually fairly simple) the rest follows easily.

    Specifically here though I mean SELinux is “simple” if you understand how Linux works and operates, as you’re constraining syscalls and access


  • SELinux is super simple, you just gotta understand how the system works.

    Once you understand the syntax and flow of SELinux policy then writing it is easy. Writing GOOD policy on the other hand …. Lmao.

    Typically most IT departments “fix” it with setenforce 0 which is the equivalent of removing the seatbelt cuz you can’t figure out how to latch it.

    Android has one of the most “robust” applications of it but it doesn’t serve the purpose a good policy does, it does add a substantial layer of defense. Apple contracted my company to come out and teach them how to SELinux a few years back. Ultimately they (companies that desire SELinux as an added layer of defense) tend to just pay “us” to do it instead lmao.












  • I think the us vs them mentality, while totally normal human behavior, is unwarranted here.

    I have tux tattooed on me because I make my living writing software predominantly for Linux, but I work from a unix system rather than Linux.

    My next gig doing the same work I will likely be required to use a windows computer as my workstation. It will be out of my hands.

    We use the tools we have, sometimes we can change our tools but more often than not people have the tools they have and ascribing your displeasure of their tool to that person is tech tribalism and part of the worst parts of human nature, even if it is over something so insignificant as which operating system someone else is using.

    I don’t feel personally attacked by you, and idk why your comment was removed.