Thread
:
REQUEST: True Application Locker
View Single Post
zimon
2010-10-07 , 16:54
Posts: 1,341 | Thanked: 708 times | Joined on Feb 2010
#
9
Actually, if Maemo5 (or Meego will) would support SELinux, pretty secure system could be done much more easily and without having (slowish and battery consuming) multiple TrueCrypted virtual disks.
The above TrueCrypt based sandboxing would be like recreating SELinux again but with little different features and by different methods.
If the root-user can decrypt every virtual disk anyway through the applock-password-manager, then just having everything else but /boot in one single crypted volume and having enforced SELinux policy would be better system, because SELinux has extra features.
To port SELinux to maemo5 is doable and would benefit in many other use cases.
Then one could just give and drop priviledges as a root user in xterminal (or in SELinux Policy GUI) before one gives a phone to a neighbour.
Quote & Reply
|
zimon
View Public Profile
Send a private message to zimon
Find all posts by zimon