<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: I love SELinux (part IV)</title>
	<atom:link href="http://www.jonmasters.org/blog/2008/07/02/i-love-selinux-part-iv/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.jonmasters.org/blog/2008/07/02/i-love-selinux-part-iv/</link>
	<description>World Organi[sz]ation Of Broken Dreams</description>
	<lastBuildDate>Thu, 01 Dec 2011 20:35:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: jcm</title>
		<link>http://www.jonmasters.org/blog/2008/07/02/i-love-selinux-part-iv/comment-page-1/#comment-131296</link>
		<dc:creator>jcm</dc:creator>
		<pubDate>Wed, 02 Jul 2008 15:27:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.jonmasters.org/blog/?p=689#comment-131296</guid>
		<description>So, you&#039;re administrating these systems...in that case these are non-typical end-user installs. Just because you understand when SELinux is breaking functionality, doesn&#039;t mean these users would figure this out on their own.

Manual pages, command line utilities, and &quot;power&quot; tools do not make a system usable for end users. Most of them do not need SELinux to protect them from rogue applications - a bug in the kernel or in a millions of lines of code not protected by SELinux will still tear down the system.

Jon.</description>
		<content:encoded><![CDATA[<p>So, you&#8217;re administrating these systems&#8230;in that case these are non-typical end-user installs. Just because you understand when SELinux is breaking functionality, doesn&#8217;t mean these users would figure this out on their own.</p>
<p>Manual pages, command line utilities, and &#8220;power&#8221; tools do not make a system usable for end users. Most of them do not need SELinux to protect them from rogue applications &#8211; a bug in the kernel or in a millions of lines of code not protected by SELinux will still tear down the system.</p>
<p>Jon.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: domg472</title>
		<link>http://www.jonmasters.org/blog/2008/07/02/i-love-selinux-part-iv/comment-page-1/#comment-131295</link>
		<dc:creator>domg472</dc:creator>
		<pubDate>Wed, 02 Jul 2008 10:23:41 +0000</pubDate>
		<guid isPermaLink="false">http://www.jonmasters.org/blog/?p=689#comment-131295</guid>
		<description>I appreciate your views. However chcon is part of coreutils like chmod and chown it has a manual page (8). Users do not run guest systems. Super users or power users do. Power users use system-config-selinux to label any objects and use restorecon to restore file objects to their types.

Why would a owner of a computer use SELinux at home? Simple, not primarily to protect himself from haxxors or even himself.... but also to protect himself or any other people that trust their personal belonging to your system, from buggy/rogue applications. More generally any system abnormalities. 

I agree that there is still much room for improvement but i am confident that SELinux is beneficial for everyone.

I do not really know other peoples opinion on what a &#039;user&#039; or a &#039;fedora user&#039; is. I consider my mother a Fedora user. She&#039;s running SElinux enforced and works in the confined user domain. I admit, she complained when she could not watch her favorite tv channel in big screen in firefox/nsplugin totem. I just told her it was just another error like so often happens and that people are working to solve any issue. A few weeks later the issue was cprrected just like i predicted and everything else works just fine. BTW my grandma runs Fedora in enforcing mode aswell. She is the user and i am the power user that is assuming administrator responsibilities over her system.</description>
		<content:encoded><![CDATA[<p>I appreciate your views. However chcon is part of coreutils like chmod and chown it has a manual page (8). Users do not run guest systems. Super users or power users do. Power users use system-config-selinux to label any objects and use restorecon to restore file objects to their types.</p>
<p>Why would a owner of a computer use SELinux at home? Simple, not primarily to protect himself from haxxors or even himself&#8230;. but also to protect himself or any other people that trust their personal belonging to your system, from buggy/rogue applications. More generally any system abnormalities. </p>
<p>I agree that there is still much room for improvement but i am confident that SELinux is beneficial for everyone.</p>
<p>I do not really know other peoples opinion on what a &#8216;user&#8217; or a &#8216;fedora user&#8217; is. I consider my mother a Fedora user. She&#8217;s running SElinux enforced and works in the confined user domain. I admit, she complained when she could not watch her favorite tv channel in big screen in firefox/nsplugin totem. I just told her it was just another error like so often happens and that people are working to solve any issue. A few weeks later the issue was cprrected just like i predicted and everything else works just fine. BTW my grandma runs Fedora in enforcing mode aswell. She is the user and i am the power user that is assuming administrator responsibilities over her system.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
