logoalt Hacker News

BpfJailer: eBPF Mandatory Access Control [pdf]

53 pointsby voxadamyesterday at 2:20 PM4 commentsview on HN

Comments

INTPenisyesterday at 5:51 PM

I can imagine that using eBPF will be faster, but I never really imagined SElinux as slow myself. I guess it's because of all the files that need to be opened, and updating policy.

They probably mean for hyper scaling environments SElinux is slow to use, it is designed for traditional servers that don't change often.

It's interesting to see my old pal SElinux be replaced.

voxadamyesterday at 3:22 PM

I've only found the slides for this talk, if anyone has video I'd love to see it.

show 1 reply