9fans - fans of the OS Plan 9 from Bell Labs
 help / color / mirror / Atom feed
From: presotto@plan9.bell-labs.com
To: 9fans@cse.psu.edu
Subject: Re: [9fans] authorization schemes (was CORBA)
Date: Wed, 26 Sep 2001 13:44:46 -0400	[thread overview]
Message-ID: <20010926174448.1D41219A3E@mail.cse.psu.edu> (raw)

The real best part was an accidental 'du /|grep pattern' by a
user at a high level user made the whole file system useless to anyone
of lower classification.

Also, terminals were a real pain because their inodes had to
change security level whenever someone new logged in, which
meant chasing down anything somehow related to them.  Not
really in the orange book model.  Network connections were
equally bad.

The real lesson of the experiment was that security level
classification is hard to live with.


             reply	other threads:[~2001-09-26 17:44 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2001-09-26 17:44 presotto [this message]
2001-09-26 17:59 ` Boyd Roberts
2001-09-27 11:04   ` Douglas A. Gwyn
  -- strict thread matches above, loose matches on Subject: below --
2001-10-02 11:11 forsyth
2001-10-01 12:24 rob pike
2001-10-01 12:48 ` Boyd Roberts
2001-10-01 12:16 rob pike
2001-10-08  9:36 ` Thomas Bushnell, BSG
2001-10-01 11:00 forsyth
2001-09-26 18:08 presotto
2001-09-26 17:39 Scott Schwartz
2001-09-26 17:55 ` Boyd Roberts
2001-09-26 19:15   ` Mike Haertel
2001-09-26 21:57     ` Boyd Roberts
2001-09-27 11:05   ` Douglas A. Gwyn
2001-09-27 11:34     ` Boyd Roberts
2001-10-01  9:49       ` Douglas A. Gwyn
2001-10-01 10:32         ` Boyd Roberts
2001-10-01 10:35         ` David Lukes
2001-10-01 14:29           ` Ronald G Minnich
2001-10-02  1:02             ` Boyd Roberts
2001-10-02  3:09               ` Ronald G Minnich
2001-10-02  8:14                 ` Boyd Roberts
2001-10-04  9:11                   ` Douglas A. Gwyn
2001-10-04  9:28                     ` Boyd Roberts
2001-10-04 10:28                       ` davel
2001-10-04 10:34                         ` Boyd Roberts
2001-10-05  8:43                       ` Douglas A. Gwyn
2001-10-02  9:05                 ` David Lukes

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20010926174448.1D41219A3E@mail.cse.psu.edu \
    --to=presotto@plan9.bell-labs.com \
    --cc=9fans@cse.psu.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).