Re: MAC before DAC vs DAC before MAC

From: Crispin Cowan (crispinat_private)
Date: Thu Jul 26 2001 - 10:58:42 PDT

  • Next message: Crispin Cowan: "Re: MAC before DAC vs DAC before MAC"

    richard offer wrote:
    > Take for example the case where a MAC check would deny access, and that the
    > time to perform DAC checks is long.
    > ... [snip]
    > When I wrote the "But we can probably live with that" I wasn't thinking
    > about ACLs, so I recant it :-)
    We can go round and round on which configuration is faster, based on various
    assumptions about which check is more complex.
    But that wasn't the question:  David & I want to know why anyone should care
    about the performance of denied accesses?
    Crispin Cowan, Ph.D.
    Chief Scientist, WireX Communications, Inc.
    Security Hardened Linux Distribution:
    Available for purchase:
    linux-security-module mailing list

    This archive was generated by hypermail 2b30 : Thu Jul 26 2001 - 14:48:28 PDT