Re: [qubes-users] Breaking the Security Model of Subgraph OS

2017-04-12 Thread cooloutac
On Wednesday, April 12, 2017 at 4:34:48 AM UTC-4, Bernhard wrote: > > What exactly makes subgraph special and not just another > > apparmor/selinux MAC type clone? > > > > The firewall is a neat bit of progress however, but again that can > > also be accomplished with an apparmor MAC default

Re: [qubes-users] Breaking the Security Model of Subgraph OS

2017-04-12 Thread Zrubi
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 04/12/2017 10:34 AM, Bernhard wrote: > I perfectly agree that this 'phone home' business is inaccaptable. > If you consider that this type of firewall is easy to set up within > qubes I invite you to write a small tutorial on the subject for >

Re: [qubes-users] Breaking the Security Model of Subgraph OS

2017-04-12 Thread Bernhard
> What exactly makes subgraph special and not just another > apparmor/selinux MAC type clone? > > The firewall is a neat bit of progress however, but again that can > also be accomplished with an apparmor MAC default profile however > allow app to access site etc is only on an IP basis not a DNS

Re: [qubes-users] Breaking the Security Model of Subgraph OS

2017-04-11 Thread taii...@gmx.com
What exactly makes subgraph special and not just another apparmor/selinux MAC type clone? The firewall is a neat bit of progress however, but again that can also be accomplished with an apparmor MAC default profile however allow app to access site etc is only on an IP basis not a DNS basis

[qubes-users] Breaking the Security Model of Subgraph OS

2017-04-11 Thread Micah Lee
I met up with Joanna at the recent Tor meeting in Amsterdam, and we tried to see if we could hack Subgraph OS, which I was running on my travel computer. We succeeded, and I've written up all the details here: https://micahflee.com/2017/04/breaking-the-security-model-of-subgraph-os/ And also