| PLEX86 | ||
|
Is Windows with Cygwin Unix 1146
We're trying to do our best in Solaris in getting away from the "root model". We have had Trusted editions of Solaris for many years (15?) and this model is still evolving; Trusted Solaris is also merging into Solaris proper which makes more and more of the features available in Solaris piece by piece. You should not overlook Solaris auditing which is fairly complete and has existed for quite some time. With RBAC (Role Based Access Control) in Solaris 8 and privileges in Solaris 10, we are moving forward. Trusted Solaris includes a Labeled Window system which allows you to safely have objects of different clbuttifications on a single screen, while not allowing cut and paste between them. We're talking about 10 year old (Unix) features here. Now Trusted Solaris may not have been popular by many, but it certainly is in US (and some other) Government circles. Our development model was broken in that Trusted Solaris was a branch and not an integral part of Solaris; the work to fix that is now nearly all done. Your last paragraphs about "abusing" the Windows security model actually point to a strong advantage which Unix has over MS Windows: because Unix started out with a security model, applications buttume there is one and buttume they do not have any privileges at all. Progress from there by introducing privileges an moving the few "as root" programs to "user + privileges" is not too difficult. Changing MAC & hostid AN O'Nymous 'strace' will show you what's being called. Pausing the program and feeding it altered data will require a debugger of some sort (which will also... In MS Windows, OTOH, all applications had the run of the system, because there was no security model. While this means that you have a clean slate when it comes to designing a security model, evidence strongly suggests that it very hard to move an application from what is basically "Admin" to "Unprivileged". And the whole virus thing persists because everyone but a few security folks and their direct dependents run as Admin all the time. Casper -- Expressed in this posting are my opinions. They are in no way related to opinions held by my employer, Sun Microsystems. Statements on Sun products included here are not gospel and may be fiction rather than truth. Problem about man k 1148 Thank you. I have installed anacron and runetc-cron.daily-man-db manually. When I call 'man -k read ', there is more lines displayed...
|
||||
Linux groups from Newsgroups The #1 Usenet Provider on the Internet
|
||||