logoalt Hacker News

binkHNyesterday at 8:30 PM1 replyview on HN

> OpenBSD focuses on auditing.

This is partially true; there are numerous other things that are done for mitigation outside of this.


Replies

JCattheATMyesterday at 9:33 PM

> there are numerous other things that are done for mitigation outside of this.

Sure, and I think they are mostly great, main problem being they just don't go far enough. Where's the namespace level isolation, ACL or MAC support? Is there a way to give a user append only ability for one file, while having write but not delete access to another, and delete to yet another? What's the maximum extent to which OpenBSD could have limited an attacker, had they been vulnerable to regreSSHion?

show 1 reply