Skip to main content
SELinux

SELinux

SoftwareWikipedia

Search complete. 12 mentions across 9 episodes found for "SELinux".

Sep 10, 2026

Paul AsadoorianHOST
111:42
operating system not just in the sense of open source but in the you should have the liberty to do what you want on the system and so it's not necessarily going to prevent you from creating these processes right unless you were to kind of glob on some other kind of security controls to that, that may enforce, you can't create a process, you know, that's named that it may prevent that they may stop some things from working, but.
Paul AsadoorianHOST
112:16
Things like SELinux and AppArmor and such are facilities in Linux that could potentially either prevent or detect this type of behavior.
Paul AsadoorianHOST
112:28
But that's left up to, in typical Linux fashion, the user to define what those rules are and or enforce them or not on your system.
Jeff MannPANELIST
112:40
Okay.
Paul AsadoorianHOST
111:35
for whom? Linux loves to be a free and open environment.
Paul AsadoorianHOST
111:42
operating system not just in the sense of open source but in the you should have the liberty to do what you want on the system and so it's not necessarily going to prevent you from creating these processes right unless you were to kind of glob on some other kind of security controls to that, that may enforce, you can't create a process, you know, that's named that it may prevent that they may stop some things from working, but, Things like SELinux and AppArmor and such are facilities in Linux that could potentially either prevent or detect this type of behavior.
Paul AsadoorianHOST
112:28
But that's left up to, in typical Linux fashion, the user to define what those rules are and or enforce them or not on your system.
Jeff MannPANELIST
112:40
Okay.
Natalie SilvanovichGUEST
8:21
And eventually we got to a place where in the context of this decoder, I could get the phone to, you know, call different functions, like maybe mem copy by the frames that were inside the audio file.
Natalie SilvanovichGUEST
8:33
And then after that, this got a bit complicated due to a security feature called SELinux, but Seth and I and another one of our co-workers, Jan Horn, worked together on this and kind of figured out the best way to go was to write code into memory and then write to a node called mself slash proc slash mem, which basically overwrote some readable memory.
Natalie SilvanovichGUEST
8:56
And then we could call it.
Natalie SilvanovichGUEST
8:57
And that was the end of the first stage.

8 MINS LATER

Natalie SilvanovichGUEST
16:44
I was like basically starting from nothing.
Natalie SilvanovichGUEST
16:47
So I think that was the thing that made this the most difficult.
Natalie SilvanovichGUEST
16:51
I talked a little bit about earlier SELinux.
Natalie SilvanovichGUEST
16:54
That's a security feature on Android.
Corey QuinnHOST
0:42
We've only been asking for this for how long again? Amazon Linux 2027 is now available in public preview, which is a big change to everyone's provisioning process.
Corey QuinnHOST
0:52
Namely, you're going to have to explicitly disable SELinux as part of your cloud init configurations.
Corey QuinnHOST
0:58
You shouldn't do that.
Corey QuinnHOST
0:59
Yes, you are correct, Eugene, but it's still the most widely disabled Linux configuration on the planet.
Paul SidorianHOST
17:59
It's out there.
Paul SidorianHOST
18:01
And one of the items I'm looking into this week is AppArmor and SELinux.
Paul SidorianHOST
18:08
And even if those were configured and installed on these platforms that run Linux and other covers that represent our network edge, you need some kind of visibility into them, right? In AppArmor, you need to know...
Paul SidorianHOST
18:24
that there's a profile for an application, what configuration state it's in, and whether or not an application protected by AppArmor has tried to violate one of the rules, access files or other things it typically isn't supposed to.
SteveHOST
41:00
And that is the digital equivalent of having every key to the building.
SteveHOST
41:04
So researchers, they found a way that, they found that the implant could inspect or write to the phone's databases, disable the ser, sec-, uh, security system known as SELinux, and switching, uh, switch off logging, block the legitimate software updates, and accept commands from a police-controlled server.
SteveHOST
41:26
And then it used a publicly available security testing tool called Frida to insert itself into the Encrochat application.
SteveHOST
41:34
And when a message was created or received, the implant, uh, could momentarily interrupt the application, copy the unencrypted text, and then send that copy to a French police server, often within seconds.
speaker_0NARRATOR
3:31
Hardening also relies on defense in depth, which means layering multiple independent security controls so that if one fails, others still protect the system.
speaker_0NARRATOR
3:39
Examples of layers include firewall rules; mandatory access control frameworks such as Security-Enhanced Linux, SELinux, or AppArmor; restrictive file permissions; strong authentication; logging and auditing; and regular patching.
speaker_0NARRATOR
3:53
No single control is trusted to be perfect.
speaker_0NARRATOR
3:56
Secure defaults and configuration baselines.
Luke HindsGUEST
27:41
And Linux landlock is what we call in LSM, the Linux Security Module.
Luke HindsGUEST
27:46
So it sits alongside SELinux and various sort of well-known security primitives in the kernel.
Luke HindsGUEST
27:54
And this again, allows you to do this file specific, network specific.
Luke HindsGUEST
27:59
sandboxing.
Herman PoppleberryHOST
4:33
V4.2 in 2014 added server-side copy, so if you want to duplicate a file on the server, The data never has to travel to the client and back.
Herman PoppleberryHOST
4:42
Also added sparse file awareness and some SELinux label support.
Herman PoppleberryHOST
4:46
And, as of right now, the IETF NFS v4 working group is actively drafting v4.3.
Herman PoppleberryHOST
4:53
So, it's not dead.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.