LIDS - joke


From: Milan WWW Pikula <www@banan.napri.sk>
Subject: LIDS - joke
Date: Mon, 4 Sep 2000 17:42:06 +0200 (CEST)

Next Article (by Date): Re: LIDS - joke Xie Huagang
Previous Article (by Date): FF bug Amon Ott
Next in Thread: Re: LIDS - joke Xie Huagang
Articles sorted by: [Date] [Author] [Subject]


Hi,

	recently I've found this statment on the LIDS home page:

What is LIDS
	...
	* B1/B2 level of the OS

great :) not only they do kernel changes without real security model,
they also lie like a gasmeter :).

I'd like the webmaster of LIDS to shout this line off, as it is
absolutely nonsensical. For B1 you need mandatory control, must have all
communication channels marked as one-level or multilevel and much more.
For B2 you also need the possibility to assign the maximum and minimum
security level to the PHYSICAL DEVICES (and some other things as well).
And after all, there are 3 steps in order to get the B1 or B2
level: Accreditation, Certification and Evaluation, done by
appropriate organisations (look at
http://www.cs.umbc.edu/~sesbra1/tsyscons.html)

I am sending this mail to authors of LIDS, and to the Medusa and RSBAC
mailing lists. Hope to see some response from LIDS team soon.

	Milan Pikula

--
Milan Pikula, WWW. Finger me for Geek Code.
http://fornax.elf.stuba.sk/~www, www@fornax.elf.stuba.sk
.. dajte mi pevnu linku a pohnem zemegulou ..


-
To unsubscribe from the rsbac list, send a mail to
majordomo@rsbac.org with
unsubscribe rsbac
as single line in the body.

Next Article (by Date): Re: LIDS - joke Xie Huagang
Previous Article (by Date): FF bug Amon Ott
Next in Thread: Re: LIDS - joke Xie Huagang
Articles sorted by: [Date] [Author] [Subject]


Go to Compuniverse LWGate Home Page.