Date: Thu, 19 Feb 2004 13:28:55 -0800 From: Ted Cabeen <secabeen@pobox.com> To: Jim Zajkowski <jim@jimz.net> Cc: freebsd-security@freebsd.org Subject: Re: Question about securelevel Message-ID: <874qtmyd0o.fsf@gray.impulse.net> In-Reply-To: <DF1C2DE5-5CA7-11D8-A225-000A95DA58FE@jimz.net> (Jim Zajkowski's message of "Wed, 11 Feb 2004 10:35:07 -0500") References: <1171.192.168.0.77.1076505166.squirrel@mail.redix.it> <79D6F861-5C96-11D8-A225-000A95DA58FE@jimz.net> <2CAA7A5D-5C9A-11D8-ADF8-0030654D97EC@patpro.net> <1295.192.168.0.77.1076513042.squirrel@mail.redix.it> <DF1C2DE5-5CA7-11D8-A225-000A95DA58FE@jimz.net>
next in thread | previous in thread | raw e-mail | index | archive | help
Jim Zajkowski <jim@jimz.net> writes: > On Feb 11, 2004, at 10:24 AM, roberto@redix.it wrote: > >> Yes I agree with you: a secure system should be read-only fs, but to >> overcome the drawbacks of a CDROM, I can use a standard hardisk with a >> read-only file system while securelevel==3. The writable file system >> should be available in single user mode only on console. > > If I figure out how to make your filesystem remount read-write without > a reboot, the game is over. Setting all of the important files on the disk immutable will help a fair bit too, but a true read-only medium is better. -- Ted Cabeen http://www.pobox.com/~secabeen ted@impulse.net Check Website or Keyserver for PGP/GPG Key BA0349D2 secabeen@pobox.com "I have taken all knowledge to be my province." -F. Bacon secabeen@cabeen.org "Human kind cannot bear very much reality."-T.S.Eliot cabeen@netcom.com
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?874qtmyd0o.fsf>