SELinux is overly complicated, but it’s not hard to at least grasp the basics
The amount of people confusing DAC and MAC is concerning. You’ve done an excellent job explaining the topic.
19 karma · joined March 30, 2024
The amount of people confusing DAC and MAC is concerning. You’ve done an excellent job explaining the topic.
This backdoor does not bypass remote authentication so it should be able to transition to the new domain that has access to these files
libselinux is just an unwitting vector to link liblzma with openssh
by default sshd has access to all files in /home/$user/.ssh/, but that could be prevented by giving private keys a new unique file context, etc.
SELinux would not prevent all attacks, but it can mitigate quite a few as part of a larger security posture