logoalt Hacker News

CraigJPerry11/08/20246 repliesview on HN

>> You can't just add them later, on top of the legacy Mac OS

SELinux managed it, what's fundamentally stopping MacOS?


Replies

acdha11/08/2024

SELinux can be part of the solution but it doesn’t solve the problem. The median Linux system is far behind the median Mac because while SELinux exists you still have to craft fine-grained policies and deal with all of the exceptions needed to have the system still be usable. This is more a function of budget than anything else.

show 1 reply
throw0101a11/08/2024

> SELinux managed it

Not when you have SELINUX=disabled (rather than SELINUX=enforcing), which is what I've seen in most environments.

Personally I've had better experiences with AppArmour.

show 1 reply
nyrikki11/08/2024

Complete different set of tradeoffs.

This is one of those situations where there is no good option, just the least worse option.

SE had mostly servers, depends on package vendors being altruistic, and people mostly just disabled it when it caused problems.

That is a very different set of assumptions and challenges than what Apple faces.

show 1 reply
lmz11/08/2024

Usability. And/or good taste.

show 1 reply
result2vino11/08/2024

Can your grandma use SELinux? Delusional.

show 4 replies
lapcat11/08/2024

There's a [dead] reply that you may not see, but frankly I kind of agree with it: "Can your grandma use SELinux? Delusional." https://news.ycombinator.com/item?id=42087188

show 1 reply