|
|
|
|
|
by frabbit
1571 days ago
|
|
> it's clear that for most lay folks, SELinux is software that doesn't work. I have always used selinux enabled systems. For the first few years it was a bit confusing and frustrating at times, but for the last (decade?) I have never had to butt heads with it. The default policies shipped by e.g. Fedora (a userland closest to the development of this work and therefore probably better maintained than some others) work out of the box without hassle. This very article refutes your assertion: here we see SELinux working for ordinary users without any additional fiddling. You, on the other hand, are probably exposed to this privilege escalation. |
|
To be clear: SELinux is an important mitigation - just like the Windows Firewall - and one should not disable either.