You are not logged in.

#1 2012-06-16 10:20:33

Evilandi666
Member
Registered: 2010-10-28
Posts: 105

Anyone using yama on 3.4.x?

Hi,

just want to know your opinion on using yama? Do you use it? Do you think it is unsecure not to do it?

Yama is a new security module in 3.4.x (current 3.4.2 in arch), which disallows ptrace from other processes than parents. Don't use that if you already use selinux etc. as yama would disable other security modules.

Usage: Add security=yama to kernelline

For more information: http://git.kernel.org/?p=linux/kernel/g … ecfbdcf8eb

I also thought about adding a wiki page for it, but I don't know if that is necessary. There is nothing "special" in Arch about it.

Offline

#2 2012-06-21 10:23:36

Evilandi666
Member
Registered: 2010-10-28
Posts: 105

Re: Anyone using yama on 3.4.x?

No answer? No one interested in "security"?

Offline

#3 2012-06-21 11:38:45

brebs
Member
Registered: 2007-04-03
Posts: 3,742

Re: Anyone using yama on 3.4.x?

Evilandi666 wrote:

No one interested in "security"?

Yes, but apparmor is better wink

Offline

#4 2012-06-21 11:52:47

graysky
Wiki Maintainer
From: :wq
Registered: 2008-12-01
Posts: 10,734
Website

Re: Anyone using yama on 3.4.x?

brebs wrote:

Yes, but apparmor is better wink

Slightly OT but what is the state of apparmor on AL today?  The wiki article is flagged as stale.

Offline

#5 2012-06-22 12:54:43

Evilandi666
Member
Registered: 2010-10-28
Posts: 105

Re: Anyone using yama on 3.4.x?

brebs wrote:
Evilandi666 wrote:

No one interested in "security"?

Yes, but apparmor is better wink

Have you checked every single AUR Package for apparmor?

For me, security things installed from AUR aren't secure at all. (same with selinux, lots of AUR Packages).

If all Selinux/Apparmor packages would be in the official repos, then I would see them as a security improvement.

Last edited by Evilandi666 (2012-06-22 12:55:12)

Offline

#6 2012-06-22 14:38:32

brebs
Member
Registered: 2007-04-03
Posts: 3,742

Re: Anyone using yama on 3.4.x?

Evilandi666 wrote:

Have you checked every single AUR Package for apparmor?

Don't be silly. Have you learnt yet that security is a layered set of compromises?

AFAICT, if Yama is enabled, AppArmor and SELinux *must* be disabled. Kernel 2.4.1's Yama.txt says:

To select it at boot time, specify "security=yama" (though this will disable any other LSM).

I'd rather e.g. protect Skype using AppArmor to make it impossible for Skype to run rampant and delete all my files in ~. Same with firefox, especially when running Flash.

Offline

#7 2012-06-22 15:58:59

Evilandi666
Member
Registered: 2010-10-28
Posts: 105

Re: Anyone using yama on 3.4.x?

brebs wrote:
Evilandi666 wrote:

Have you checked every single AUR Package for apparmor?

Don't be silly. Have you learnt yet that security is a layered set of compromises?

AFAICT, if Yama is enabled, AppArmor and SELinux *must* be disabled. Kernel 2.4.1's Yama.txt says:

I think using yama is better than using nothing, I didn't use anything before.

If you don't check every PKGBUILD you install (especially for security things like apparmor etc.), then you're making a quite big compromise in my opinion ... wink

Offline

#8 2012-06-22 17:00:03

brebs
Member
Registered: 2007-04-03
Posts: 3,742

Re: Anyone using yama on 3.4.x?

You'd be making a big compromise, by choosing Arch rather than e.g. OpenBSD wink

Although OpenBSD also includes ptrace - the horror! It must be wide-open to attack.

I'm going to turn my computer off now, to be safe, and I recommend you all do the same.

Offline

Board footer

Powered by FluxBB