SELinux managed it, what's fundamentally stopping MacOS?
SELinux managed it, what's fundamentally stopping MacOS?
Hold on that’s changing the goalposts a bit here. SELinux doesn’t solve this problem on RHEL boxes by virtue of just existing. It is the tool that Redhat uses to solve the problem. And they have solved the problem by using this tool. To the point that for years now, by default, RH boxes are installed in enforcing mode.
>> The median Linux system is far behind the median Mac
I’m not really interested in the median because for better or worse, Redhat is the most serious game in town for SELinux. Comparing Mac to RHEL, there’s only one place where Mac is ahead and that is a default Mac install at least on Apple silicon will have an immutable root. Redhat has irons in the fire here (rpm ostree can infuturue unlock a user friendly immutable root). Of course you can do immutable root today (and immutable usr and even epehemeral var if you want), but I’m not going to argue those are user friendly. An experienced sysadmin will take a minute to flip over between immutable root file systems during an upgrade process.
>> This is more a function of budget than anything else.
Agreed, but the Apple chequebook looks plenty beefy.
They’ve shipped it, yes. It doesn’t count as solved until all of the apps are running with policies which actually block attacks like this, just as having a fire extinguisher on the shelf doesn’t mean your fire is guaranteed to be out.
> Comparing Mac to RHEL, there’s only one place where Mac is ahead and that is a default Mac install at least on Apple silicon will have an immutable root.
Also they have far more common use of sandboxing for applications (including the harder bits about selective permissions for apps), code signing, memory protection, pervasive use of HSM and robust layered storage encryption, etc. – all out of the box, whereas even in the much easier case of servers you’re looking at many hours of skilled labor to configure an equivalent.
My point about budgets is that this is just a lot of work. Apple’s not perfect but a lot of people have a mental model from the 2000s which is no longer true.
not even, it's android. Yeah, their policies are airtight
SELinux on Red Hat only confines web servers, DNS servers and such. All software started by an interactive user, including web browsers, runs in the "unconfined" domain (term?), which means SELinux is not even trying to contain that software.
ChromeOS OTOH does use selinux to sandbox the browser (and IIUC Android uses it to sandbox every app).
>Comparing Mac to RHEL, there’s only one place where Mac is ahead
That's not my understanding: Mac is far from perfect, but it is more secure overall than RHEL and Fedora IMO. It's not just that the Mac verifies the integrity of /usr and such whereas Linux distros do not.
Not when you have SELINUX=disabled (rather than SELINUX=enforcing), which is what I've seen in most environments.
Personally I've had better experiences with AppArmour.
Yeah of course, but by default Redhat will install in enforcing mode. This is taking a horse to water, the drinking is left to the horse.
This is one of those situations where there is no good option, just the least worse option.
SE had mostly servers, depends on package vendors being altruistic, and people mostly just disabled it when it caused problems.
That is a very different set of assumptions and challenges than what Apple faces.
(1) apples context is obviously different
Normal people's use cases for their computer is light file management, light document and productivity workflows and everything else is done in the browser. Hell, most of the document processing and productivity crap is in the browser these days too.
That's rather self critical of you, even if deserved.
My grandma also can't write software, or really do anything advanced, no should she be able to. SELinux, just like any other security and/or containerization technology, is supposed to be used by developers, sysadmins, distribution maintainers. Not by end users.
Is the macos sandbox the odd one out? I'm not familiar with it, but find it very hard to believe that "my grandma" is its target audience.
You can't compare Android to macOS. Compare Android to iOS, which had many more limitations built-in from the start than macOS.
Incidentally, this is why iPad has never become the desktop replacement everyone claimed it would be. The hardware is plenty powerful, but it's always been very limited by the software. The greater freedom and capabilities of macOS is a huge advantage for desktop-class functionality.
If I could continue to run Emacs, e.g., in a VM like WSL2 or Crostini, I'd probably switch right away. If not, it would take me a year or 2 to transition to a replacement before I switch (and, no, that replacement would not need to be able to run software written in Emacs Lisp: I'd be happy to replace, rewrite or walk away from any functionality I currently get from code written in Emacs Lisp).
The current model, where executables can access any user file or resource, needs to go. We haven't learned anything from e.g. compromised pip packages that stole ssh keys.
Thing is that Android is probably no more secure than a standard desktop experience specifically due to the very uncontained Play Store, the prevalence of sideloading apps and rooting doesn't really help at all.
Do you have an opinion on whether GrapheneOS is more secure than a standard desktop experience?
>complete with floating windows
The irony is that I don't even use floating windows on my (Gnome) Linux install: I maximize all the windows as if it were iPadOS or something.
This is completely untrue. There is lot more to OS security than where software can be downloaded from. The point about root and sideloading is completely missing the point as those are even worse on desktop operating systems. On desktops you can basically run whatever from wherever and there is usually no sandboxing at all. On Android, there is a strict sandbox and you can't run whatever you want. Android is not rooted by default.
Every app is strictly sandboxed on Android, point me to a desktop OS that has anything close to that. Every process is confined using SELinux policies on Android, which desktop OS has as strict MAC setup? Android has a proper, working verified boot, which desktop OS has something similar? Not to mention all the other hardening and exploit mitigations that are usually completely missing from standard desktop operating systems.
They basically do now?
On iOS I've never seen a BT keyboard not pair and I've never had problems with external monitors. Sometimes getting the right dongle so it plugs in is the bigger problem, but iPads have been USB-C for a while now, making it pretty much a non-issue, whenever I've tried.
I haven't tried with Android in a while, but I'd be surprised if it's much different than iOS at this point in time.
Is using a mouse with Mobile Safari a pleasant experience if the user is doing many hours of interaction that way?
(Actually, now that I think about it, iPadOS is too restrictive for me: I can't configure it in ways I would want to, but GrapheneOS doesn't have that problem what with being almost entirely open-source.)
Well, since the iPad display is also the touchpad, you probably don't want to never interact with the iPad display. But essentially yes. Some TV's have a worse time than others. iPad's can't control what the TV can handle. In general, I've never had big problems, though I don't use it for 8hr work sessions.
> Is using a mouse with Mobile Safari a pleasant experience if the user is doing many hours of interaction that way?
If you are on macOS you can just scroll your mouse cursor over to the iPad and find out yourself. See: https://support.apple.com/en-us/102459
Nobody can tell you if what they have implemented now, works well enough for you. I use it regularly, it works great.
> (Actually, now that I think about it, iPadOS is too restrictive for me: I can't configure it in ways I would want to, but GrapheneOS doesn't have that problem what with being almost entirely open-source.)
backing out already?! :) Seriously though, you are not alone. iPadOS is restrictive, that is either a bonus or a curse. It does let you focus more on tasks, but it limits how you are used to working in ways that might be hard to handle(especially at first).
I agree about GrapheneOS.
As for emacs, you can run it under iSH on iPadOS. I can't tell you how well it works, since I don't use emacs.
>iPadOS is restrictive, that is either a bonus or a curse. It does let you focus more on tasks
I used to compress my browser's executable as a way of "disabling" it. That stopped working smoothly after MacOS locked down the /Applications directory, but I found other ways to disable my browser: on Gnome now, I wrote a command that is easy to invoke and that removes browsers from "the Dash" (Gnome's analog to the Dock). (The command is implemented with `gsettings set org.gnome.shell favorite-apps`.)
Note that this method of "disabling" the browser does not prevent me from starting the browser with a command line entered into a terminal window, but it does stop me from starting the browser in a way that requires no thinking from me (i.e., the way I habitually do it) which turns out to be enough to prevent me from wasting time in the browser.
Being able to easily "disable" the browser (or more precisely, to easily arrange it so that I need to think in order to switch to a browser window) has significantly reduced the amount of time I waste online. Of course, there are times when some pressing task requires use of a web browser (which might coincide with one of the times when my ability to resist the temptation to waste time on the web is low) but in my life, those times are rare.
Yes, iPadOS offers a way to disable Safari, too, but the difference is that doing it on iPadOS requires many steps, and it hard for me to muster the self-discipline to go through the steps after I've noticed my ability to stay focused has gotten so low that I should disable my browser: the steps are this: go to Settings > Screen Time > content & privacy restrictions. Toggle on the button at the top of the pane. Enter a 4-digit passcode.
There is no way for me to customize my iPad to make it easier for me to disable Safari.
This relative lack of customizability is why I would hesitate to try to rely on iPadOS for productivity. (Currently my iPad is almost entirely an entertainment and distraction device. When I need to be productive and feel that my ability to resist the temptation to waste time on it is low, I can and do move my iPad to another room.)
You can also just limit your browser time: https://discussions.apple.com/thread/8546412?sortBy=rank