5 ms·
I’ve had that POS SELinux block me from logging directly into the console with root (nothing wrong with the pwd). Thank VMware for snapshots. I hate SELinux. B
by iluvcommunism 2y ago
I’ve had that POS SELinux block me from logging directly into the console with root (nothing wrong with the pwd). Thank VMware for snapshots. I hate SELinux.
But the job requires it.
As for people who seem to love it so much, they probably don’t have to deal with it all the time.
- ruthmarx 2y ago> As for people who seem to love it so much, they probably don’t have to deal with it all the time. Or they put in the time to learn it so they don't get frustrated when they get blocked by something, because they know how to resolve it.
- hooverd 2y agoI wish I had the hours to dedicate to every single technology I'm using, but alas...
- ruthmarx 2y agoThis is one of those technologies that people shouldn't be using if they didn't take the time to learn it. It's not like say, nginx or a linux distro, where you don't need to know the ins and outs to get it up and running.
- DrillShopper 2y agoThe problem is that when people don't know how to use it and instead turn it off they're immediately deluged from every side with pathetic nerds screaming that YOU DONT HAVE TO TURN IT OFF ANYMORE RUN THIS ARCANE SEQUENCE OF COMMADS THAT YOU DONT UNDERSTAND AS ROOT AND THAT WILL FIX THE ONE ISSUE YOU HAVE without understanding that not every computer system needs to be locked as tight as a server that's being shared with a bunch of untrusted users who are running god knows what.
- ruthmarx 2y agoWhy use RHEL if you don't want one of the main advantages it offers? There have been numerous exploits that RHEL has been protected against because of SELinux and their policies. Sure, not all servers need to be secured, but why use RHEL then? Why not use Debian or some RH fork that doesn't have it on by default, or even SuSE? The people who disable it out of convenience are generally bad admins, and generally being lazy and/or incompetent.
- DrillShopper 2y agoThank goodness you're here to tell them that. It would really be a shame if they did threat modeling and determined it was not necessary for their use case. That would make you look goofy and kind of a jerk.
- ruthmarx 2y agoHeh. Yeah, people mostly disable SELinux because they did threat modeling and determined it made sense, and don't just switch it off due to laziness or incompetence. I think claiming that is a pretty goofy argument, personally.
- _factor 2y agoWe can’t ask every car driver to be a mechanic. Specialization is born of finite time and is valuable.
- iluvcommunism 2y ago“Just learn to use it bro” constantly breaks Yeah ok.
- DrillShopper 2y agoFollowed by "surely the year of the Linux desktop is at hand!" I'm not going to link it here given his disdain for this site but jwz at least got the CADT development right. If you stop fucking rewriting things every couple of years then maybe the average user could catch their breath and catch up but if you keep changing things that don't need changing (ALSA -> PulseAudio -> pipewire -> whatever is already in the works to replace pipewire) instead of ACTUALLY FIXING THEM then you lose the right to be surprised when someone just trying to use their computer just gives up.
- wtay 2y ago> but if you keep changing things that don't need changing (ALSA -> PulseAudio -> pipewire -> whatever is already in the works to replace pipewire) instead of ACTUALLY FIXING THEM This is possibly the dumbest thing I read in a while... 1. PipeWire was written to fix PulseAudio and is a drop in upgrade. How do you think things get fixed otherwise? 2. Why would anyone rewrite PipeWire at the moment, why would you think that?
- DrillShopper 2y ago1. By fixing ALSA or PulseAudio instead of writing pipewire 2. Because writing something new is easier than trying to understand something already written. Maintenance is not sexy. Writing new things is.
- 2y ago