<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Preventing Disclosure</title>
	<atom:link href="http://www.usefulsecurity.com/2007/08/preventing-disclosure/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.usefulsecurity.com/2007/08/preventing-disclosure/</link>
	<description>Solving real security problems that matter to real users</description>
	<pubDate>Mon, 06 Sep 2010 23:27:42 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: c-had</title>
		<link>http://www.usefulsecurity.com/2007/08/preventing-disclosure/#comment-39</link>
		<dc:creator>c-had</dc:creator>
		<pubDate>Fri, 12 Sep 2008 03:18:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.usefulsecurity.com/?p=15#comment-39</guid>
		<description>Marcelo:
The example above does not place any requirements on the end user. Authentication is performed by the web application itself, and that web application controls access to its data. The point of the above is that I used SELinux to prevent any other web app from accessing this web app's private data.

Note that there are ways to utilize remote SELinux contexts between two cooperating SELinux systems, but they are not useful in your average web application due to that need to have cooperating systems. This is a much simpler example. If you're interested in using remote SELinux contexts between SELinux systems to enforce multi-system policies, I suggest you check out http://securityblog.org/brindle/2007/05/28/secure-networking-with-selinux/</description>
		<content:encoded><![CDATA[<p>Marcelo:<br />
The example above does not place any requirements on the end user. Authentication is performed by the web application itself, and that web application controls access to its data. The point of the above is that I used SELinux to prevent any other web app from accessing this web app&#8217;s private data.</p>
<p>Note that there are ways to utilize remote SELinux contexts between two cooperating SELinux systems, but they are not useful in your average web application due to that need to have cooperating systems. This is a much simpler example. If you&#8217;re interested in using remote SELinux contexts between SELinux systems to enforce multi-system policies, I suggest you check out <a href="http://securityblog.org/brindle/2007/05/28/secure-networking-with-selinux/" rel="nofollow">http://securityblog.org/brindle/2007/05/28/secure-networking-with-selinux/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcelo</title>
		<link>http://www.usefulsecurity.com/2007/08/preventing-disclosure/#comment-38</link>
		<dc:creator>Marcelo</dc:creator>
		<pubDate>Wed, 10 Sep 2008 13:22:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.usefulsecurity.com/?p=15#comment-38</guid>
		<description>I would like to know if, in order for this example to run properly, the web page user should also be running a system with SELinux, or it could be any client.
How, is the authentication done if the user is not using SELinux? How do you know his SecurityContext? Or you solved the authentication in a DAC way?
Thanks!</description>
		<content:encoded><![CDATA[<p>I would like to know if, in order for this example to run properly, the web page user should also be running a system with SELinux, or it could be any client.<br />
How, is the authentication done if the user is not using SELinux? How do you know his SecurityContext? Or you solved the authentication in a DAC way?<br />
Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: c-had</title>
		<link>http://www.usefulsecurity.com/2007/08/preventing-disclosure/#comment-3</link>
		<dc:creator>c-had</dc:creator>
		<pubDate>Wed, 22 Aug 2007 14:29:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.usefulsecurity.com/?p=15#comment-3</guid>
		<description>I'm sorry you couldn't understand some of the parts. If you have any specific questions, please post them and I'll do my best to answer them.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry you couldn&#8217;t understand some of the parts. If you have any specific questions, please post them and I&#8217;ll do my best to answer them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://www.usefulsecurity.com/2007/08/preventing-disclosure/#comment-2</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Fri, 17 Aug 2007 16:08:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.usefulsecurity.com/?p=15#comment-2</guid>
		<description>I couldn't understand some parts of this article nting Disclosure at  Useful Security, but I guess I just need to check some more resources regarding this, because it sounds interesting.</description>
		<content:encoded><![CDATA[<p>I couldn&#8217;t understand some parts of this article nting Disclosure at  Useful Security, but I guess I just need to check some more resources regarding this, because it sounds interesting.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
