From owner-freebsd-security@FreeBSD.ORG Thu Feb 19 13:28:55 2004 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5D3CB16A4CE for ; Thu, 19 Feb 2004 13:28:55 -0800 (PST) Received: from gray.impulse.net (gray.impulse.net [207.154.64.174]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5607143D1D for ; Thu, 19 Feb 2004 13:28:55 -0800 (PST) (envelope-from secabeen@pobox.com) Received: by gray.impulse.net (Postfix, from userid 1000) id 2F065330; Thu, 19 Feb 2004 13:28:55 -0800 (PST) To: Jim Zajkowski References: <1171.192.168.0.77.1076505166.squirrel@mail.redix.it> <79D6F861-5C96-11D8-A225-000A95DA58FE@jimz.net> <2CAA7A5D-5C9A-11D8-ADF8-0030654D97EC@patpro.net> <1295.192.168.0.77.1076513042.squirrel@mail.redix.it> From: Ted Cabeen Date: Thu, 19 Feb 2004 13:28:55 -0800 In-Reply-To: (Jim Zajkowski's message of "Wed, 11 Feb 2004 10:35:07 -0500") Message-ID: <874qtmyd0o.fsf@gray.impulse.net> User-Agent: Gnus/5.1006 (Gnus v5.10.6) XEmacs/21.4 (Reasonable Discussion, berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-Mailman-Approved-At: Fri, 20 Feb 2004 02:24:54 -0800 cc: freebsd-security@freebsd.org Subject: Re: Question about securelevel X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 19 Feb 2004 21:28:55 -0000 Jim Zajkowski writes: > On Feb 11, 2004, at 10:24 AM, roberto@redix.it wrote: > >> Yes I agree with you: a secure system should be read-only fs, but to >> overcome the drawbacks of a CDROM, I can use a standard hardisk with a >> read-only file system while securelevel==3. The writable file system >> should be available in single user mode only on console. > > If I figure out how to make your filesystem remount read-write without > a reboot, the game is over. Setting all of the important files on the disk immutable will help a fair bit too, but a true read-only medium is better. -- Ted Cabeen http://www.pobox.com/~secabeen ted@impulse.net Check Website or Keyserver for PGP/GPG Key BA0349D2 secabeen@pobox.com "I have taken all knowledge to be my province." -F. Bacon secabeen@cabeen.org "Human kind cannot bear very much reality."-T.S.Eliot cabeen@netcom.com