Landlock LSM: Sandboxen ohne Root – Praxis und Beispiele
Landlock LSM: Sandboxing im Kernel ohne root Wir vertrauen Software blind. Ein Update, eine scheinbar harmlose .deb -Datei oder ein schnell heruntergeladener Python-Skript vom Server des Kunden – oft läuft das ganze Chaos mit vollen Benutzerrechten ab. Im Linux-Umfeld gab es lange nur AppArmor oder SELinux, um da etwas Ordnung reinzubringen. Doch beide erfordern Administratorrechte und viel…
Landlock LSM is a new Mandatory Access Control (MAC) in the Linux kernel, version 5.13 and above, allowing processes to restrict their own file access permissions without requiring root privileges. This innovative approach offers a more secure alternative to traditional Linux Security Modules like AppArmor and SELinux, which require administrative rights and extensive configuration.
By enabling Landlock, users can sandbox their applications and limit their access to specific files and directories, reducing the attack surface and improving overall system security.
Brief written by urgent.news from Dev.to's own syndicated text. Machine-written — may contain errors; check the original before relying on it.