Solaris 11 has the security solution Linus wants for Desktop Linux
blogs.oracle.com
blogs.oracle.com
I've been using Linux on the desktop for quite some time now, and couldn't be happier. However I come to realize, after trying to "convert" a lot of people around me, Unix isn't made for the "desktop" (understand, unfortunately, Windows-clone).
I also use Solaris (10, not 11m but still) at work. All the time. And if Linux isn't that great on the desktop, Solaris is a catastrophe.
I'm not being very convincing, as the points I'm mentionning would take a whole blog post to prove. My question here is the following:
If this article is on the Oracle website, could it mean that the people at Redwood are trying to be more agressive on the desktop market? Or are they simply using Linus' name to attract traffic?
And as a regular Linux desktop user I must admit that one of the remaining rough edges (couldn't think of a better term) in the desktop experience of some distros is precisely what Linus is referenced as railing against.
Eh. I worked for a (small) company where Solaris was -the- desktop OS. Windows only made inroads because some clients required we do CAD work on tools that were Windows only.
It wasn't so bad. As a sysadmin ... I kind of miss it.
Note the disclaimer at the bottom:
The views expressed on this blog are those of the author and do not necessarily reflect the views of Oracle.Linux already has RBAC - if you look in /etc/group, you will see a group "lpadmin", if you are in the group, you can add/configure/delete printers (after authenticating with your user password). To the best of my knowledge, this is what Oracle is bragging about, and is equivalent to Microsoft's UAC (with Win7, they finally made it as convenient as linux).
Edit: Just to add, the key thing that they appear to be bragging about is that they use RBAC to grant the user logged into the system console the "Console User" profile which by default has permissions to modify printers and wireless connections. Once you have this role, you don't not need to authenticate further.
"yeah, there's a separation between root and user, but... there's only one user account ... and its password is the same as the root accounts password thanks to sudo ..."
This is true of Ubuntu, but not of Debian.
https://blogs.oracle.com/gbrunett/entry/enforcing_a_two_man_rulehttp://www.freedesktop.org/wiki/Software/PolicyKit
The Wikipedia page works very well as TL;DR: http://en.wikipedia.org/wiki/PolicyKit
I wonder if things are any different with Solaris 11, or more likely I'd be running OpenIndiana which so far has worked really well for the server work I have it doing.
Obviously it sounds like Unix had more fine-grained controls earlier than Windows did, but it still seems like Microsoft could write this same article on behalf of Linus.
Unless of course you're basing your claims on a definition of "capabilities" that limits that application specifically to capsicum.
I would encourage you to read more about RBAC as it is not as limited as you seem to be implying.
What Oracle is bragging about is that some parts of Solaris 11 are saner than OpenSuSe's. Having deployed to SuSe machines a couple times in the past, that's one thing I don't find particularly hard to believe. I have no direct experience with Solaris since version 8 or so. I did enjoy using OpenSolaris and OpenIndiana for a while and would consider deploying them on my home server, as soon as I build it.
I also find Linus' attitude towards fixing the problem rather than ditching the distro commendable. I wouldn't give most distros a second chance after giving me a tiny fraction of the problems he describes in his own rant. After the problems I experienced, I didn't even give OpenSuSe a first chance on my own machines. Life is too short to bitch on Bugzilla.
Read his original rant, as babarock suggested:
https://plus.google.com/u/0/102150693225130002912/posts/1vyf...
http://fedoraproject.org/wiki/Features/CupsPolicyKitIntegrat...
For example, RBAC can prevent a process from performing any network operations. Read the blog entry for more information.
Still, you don't need to give the root password (Linus' rant) with sudo and you'd have to maliciously use the programs you need to run. So, while in theory, your printer configuration utility could increase your privileges under sudo, I'm not aware of any such printer configuration utilities.