Conversation

Doing some research: on what devices or Linux distros is SELinux enabled by default, besides Android devices?
1
Replying to and
Android uses MLS in addition to MAC. Apps run with a per-user, per-app MLS security level. It also uses it for enforcing IPC security policies including via userspace enforcement. It's not an additional security layer. It's core to the privacy and security approach throughout.
1
Replying to and
It's not because Fedora / RHEL are doing SELinux wrong but because they don't have a well-defined base OS developed together with SELinux as a core part of it. It's a drastically different beast when every app has to target a well-defined sandbox and the OS is built around it.
1
Show replies