Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1758619AbZFCQsU (ORCPT ); Wed, 3 Jun 2009 12:48:20 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1754029AbZFCQsG (ORCPT ); Wed, 3 Jun 2009 12:48:06 -0400 Received: from smtp1.linux-foundation.org ([140.211.169.13]:55635 "EHLO smtp1.linux-foundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753592AbZFCQsF (ORCPT ); Wed, 3 Jun 2009 12:48:05 -0400 Date: Wed, 3 Jun 2009 09:47:23 -0700 (PDT) From: Linus Torvalds X-X-Sender: torvalds@localhost.localdomain To: Rik van Riel cc: "Larry H." , Christoph Lameter , Stephen Smalley , linux-mm@kvack.org, Alan Cox , linux-kernel@vger.kernel.org, pageexec@freemail.hu Subject: Re: Security fix for remapping of page 0 (was [PATCH] Change ZERO_SIZE_PTR to point at unmapped space) In-Reply-To: <4A26A689.1090300@redhat.com> Message-ID: References: <20090530192829.GK6535@oblivion.subreption.com> <20090530230022.GO6535@oblivion.subreption.com> <20090531022158.GA9033@oblivion.subreption.com> <20090602203405.GC6701@oblivion.subreption.com> <1244041914.12272.64.camel@localhost.localdomain> <20090603162831.GF6701@oblivion.subreption.com> <4A26A689.1090300@redhat.com> User-Agent: Alpine 2.01 (LFD 1184 2008-12-16) MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 940 Lines: 24 On Wed, 3 Jun 2009, Rik van Riel wrote: > > Would anybody paranoid run their system without SELinux? You make two very fundamental mistakes. The first is to assume that this is about "paranoid" people. Security is _not_ about people who care deeply about security. It's about everybody. Look at viruses and DDoS attacks - the "paranoid" people absolutely depend on the _non_paranoid people being secure too! The other mistake is to think that SELinux is sane, or should be the default. It's a f*cking complex disaster, and makes performance plummet on some things. I turn it off, and I know lots of other sane people do too. So the !SElinux case really does need to work. Linus -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/