Android 4.2 to include SE Linux and other security features
androidpolice.com
androidpolice.com
Try to get any information at all about /home/bofh while you're logged in.
It's a great move for security, as a well-configured SELinux deploy can provide much finer-grained access control than standard Unix permissions (although, given that Android uses the Unix user & permission model a bit abnormally, I don't know if it will bring benefit over that or not).
OTOH, for locked devices, it gives vendors more tools to prevent rooting.
Anyone else negatively impacted by this?
The most recent one I can remember was configuring Postfix to perform local delivery to ~/.local-mail/inbox. I had to manually change security context for that directory. Or linking /var/www/foo to ~/foo is an example of something that you might expect to work, but would be blocked by SELinux.
But those are not the kind of things you would do on Android anyway. They use SELinux to strengthen the security framework they already have in place. SELinux is just the last line of defence for implementation bugs and things they might have missed. It would be completely unintrusive.
The NSA presentation is worth watching, they go through various Android exploits that could have been prevented by the policy they developed, without actually targeting those specific exploits.
https://www.nsa.gov/research/selinux/
[1] It’s also because it unfortunately isn’t actually used by most desktop applications, with some exceptions, like Chromium.
i'm familiar with it, i've written some policies in it, i remember when it was introduced. that said ... i don't use it.
Also, if you disable it, re-enabling requires that you relabel all of your files and reboot the system; the relabel process can take an impressive amount of time.
Switching between eforcing and permissive can be done on the fly with the setenforce command, no reboot required.
I do think that laziness is a virtue in a sysadmin when properly applied, but using selinux is in your best interest.
In reality it's not a tiny amount of work unless you're dealing with a single server. It's not a small amount of information to learn either. And it can have pretty bad effects if you happen to cut off your access by accident. So no, can't agree with the clueless admins comment.
It's the Verified By Visa of OS security.