<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Theoretical Attack Vector?</title>
	<atom:link href="http://michaeldehaan.net/2009/11/20/theoretical-attack-vector/feed/" rel="self" type="application/rss+xml" />
	<link>http://michaeldehaan.net/2009/11/20/theoretical-attack-vector/</link>
	<description>It's Not Just About Llamas</description>
	<lastBuildDate>Tue, 24 Jan 2012 15:14:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: mpdehaan</title>
		<link>http://michaeldehaan.net/2009/11/20/theoretical-attack-vector/#comment-1312</link>
		<dc:creator><![CDATA[mpdehaan]]></dc:creator>
		<pubDate>Sat, 21 Nov 2009 14:32:25 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldehaan.net/?p=1444#comment-1312</guid>
		<description><![CDATA[Perhaps.... although that&#039;s not as easy as saying &quot;rollback to timestamp&quot; as you&#039;d still have to parse the log.    That all being said, it shouldn&#039;t be possible to begin with.]]></description>
		<content:encoded><![CDATA[<p>Perhaps&#8230;. although that&#8217;s not as easy as saying &#8220;rollback to timestamp&#8221; as you&#8217;d still have to parse the log.    That all being said, it shouldn&#8217;t be possible to begin with.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Leif</title>
		<link>http://michaeldehaan.net/2009/11/20/theoretical-attack-vector/#comment-1311</link>
		<dc:creator><![CDATA[Leif]]></dc:creator>
		<pubDate>Sat, 21 Nov 2009 05:40:40 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldehaan.net/?p=1444#comment-1311</guid>
		<description><![CDATA[&quot; and I wouldn’t know exactly what they installed so I could clean up after.&quot;

/var/log/yum.log ?]]></description>
		<content:encoded><![CDATA[<p>&#8221; and I wouldn’t know exactly what they installed so I could clean up after.&#8221;</p>
<p>/var/log/yum.log ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mpdehaan</title>
		<link>http://michaeldehaan.net/2009/11/20/theoretical-attack-vector/#comment-1310</link>
		<dc:creator><![CDATA[mpdehaan]]></dc:creator>
		<pubDate>Fri, 20 Nov 2009 14:34:58 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldehaan.net/?p=1444#comment-1310</guid>
		<description><![CDATA[I think SELinux is attempting to provide a language agnostic sandbox, the trick is to just make it automatic enough to run Pong in it automatically, and keep people from having to write policy ... ever.]]></description>
		<content:encoded><![CDATA[<p>I think SELinux is attempting to provide a language agnostic sandbox, the trick is to just make it automatic enough to run Pong in it automatically, and keep people from having to write policy &#8230; ever.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ddd</title>
		<link>http://michaeldehaan.net/2009/11/20/theoretical-attack-vector/#comment-1309</link>
		<dc:creator><![CDATA[ddd]]></dc:creator>
		<pubDate>Fri, 20 Nov 2009 13:58:37 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldehaan.net/?p=1444#comment-1309</guid>
		<description><![CDATA[Of course requiring root to install software is a &quot;arse covering&quot; thing...  A bit like &quot;show the list of updates and decide whether to patch the machine&quot; as if the user has a clue.

If software doesn&#039;t have root components there shouldn&#039;t be a problem (heck Fedora ships with user accessible gcc right?).

This is the new computing world.  You don&#039;t need permission from root to view www.filbert.com, why is this more or less safe than downloading and playing pong?  Security of a user&#039;s data is Selinux&#039;s problem !not! an excuse for a &quot;click ok to continue&quot; dialog because we still haven&#039;t got to where java was in netscape 2.0...]]></description>
		<content:encoded><![CDATA[<p>Of course requiring root to install software is a &#8220;arse covering&#8221; thing&#8230;  A bit like &#8220;show the list of updates and decide whether to patch the machine&#8221; as if the user has a clue.</p>
<p>If software doesn&#8217;t have root components there shouldn&#8217;t be a problem (heck Fedora ships with user accessible gcc right?).</p>
<p>This is the new computing world.  You don&#8217;t need permission from root to view <a href="http://www.filbert.com" rel="nofollow">http://www.filbert.com</a>, why is this more or less safe than downloading and playing pong?  Security of a user&#8217;s data is Selinux&#8217;s problem !not! an excuse for a &#8220;click ok to continue&#8221; dialog because we still haven&#8217;t got to where java was in netscape 2.0&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: louparoublond</title>
		<link>http://michaeldehaan.net/2009/11/20/theoretical-attack-vector/#comment-1308</link>
		<dc:creator><![CDATA[louparoublond]]></dc:creator>
		<pubDate>Fri, 20 Nov 2009 07:38:57 +0000</pubDate>
		<guid isPermaLink="false">http://michaeldehaan.net/?p=1444#comment-1308</guid>
		<description><![CDATA[BSD ports suffer frpm the same problems. *BSD is secure bexause the devs have fine grained control of the stack.]]></description>
		<content:encoded><![CDATA[<p>BSD ports suffer frpm the same problems. *BSD is secure bexause the devs have fine grained control of the stack.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

