• Scoopta@programming.dev
    link
    fedilink
    arrow-up
    18
    ·
    23 hours ago

    SELinux breaks a lot of android root exploits, way back in the day even dirty cow didn’t work. It would get you “root” but not actually the full perms because of SELinux. Really good testament to the added security of MAC, it’s one of the reasons I run apparmor on my systems

    • village604@adultswim.fan
      link
      fedilink
      English
      arrow-up
      2
      ·
      edit-2
      12 hours ago

      I’ll be happy if I never have to look at SELinux or fapolicy ever again. Especially fapolicy because the documentation is shit.

      It’s the one thing I don’t miss about being a sysadmin.