Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 19 Feb 2004 13:28:55 -0800
From:      Ted Cabeen <secabeen@pobox.com>
To:        Jim Zajkowski <jim@jimz.net>
Cc:        freebsd-security@freebsd.org
Subject:   Re: Question about securelevel
Message-ID:  <874qtmyd0o.fsf@gray.impulse.net>
In-Reply-To: <DF1C2DE5-5CA7-11D8-A225-000A95DA58FE@jimz.net> (Jim Zajkowski's message of "Wed, 11 Feb 2004 10:35:07 -0500")
References:  <1171.192.168.0.77.1076505166.squirrel@mail.redix.it> <79D6F861-5C96-11D8-A225-000A95DA58FE@jimz.net> <2CAA7A5D-5C9A-11D8-ADF8-0030654D97EC@patpro.net> <1295.192.168.0.77.1076513042.squirrel@mail.redix.it> <DF1C2DE5-5CA7-11D8-A225-000A95DA58FE@jimz.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Jim Zajkowski <jim@jimz.net> writes:

> On Feb 11, 2004, at 10:24 AM, roberto@redix.it wrote:
>
>> Yes I agree with you: a secure system should be read-only fs, but to
>> overcome the drawbacks of a CDROM, I can use a standard hardisk with a
>> read-only file system while securelevel==3. The writable file system
>> should be available in single user mode only on console.
>
> If I figure out how to make your filesystem remount read-write without
> a reboot, the game is over.

Setting all of the important files on the disk immutable will help a
fair bit too, but a true read-only medium is better.

-- 
Ted Cabeen           http://www.pobox.com/~secabeen            ted@impulse.net 
Check Website or Keyserver for PGP/GPG Key BA0349D2         secabeen@pobox.com
"I have taken all knowledge to be my province." -F. Bacon  secabeen@cabeen.org
"Human kind cannot bear very much reality."-T.S.Eliot        cabeen@netcom.com



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?874qtmyd0o.fsf>