View Single Post
  #8   (View Single Post)  
Old 7th November 2008
hydra's Avatar
hydra hydra is offline
Port Guard
 
Join Date: May 2008
Location: Slovakia (Europe)
Posts: 41
Default

Hey tanked, I know how you feel. I was the same when reading it

Ok, but MAC is not just as file permissions. First of all, Unix has DAC - the user can choose what files have what permission. In MAC, it's enforced by the system what permission one has. The MAC implementation in FreeBSD also allows things like binding non-privilaged apps to ports bellow 1024.

With MAC it's possible to do the following: suppose you have students and a teacher.
Students will be able to write to the teacher, but not be able to read from the teacher.
The teacher will be able to read from the students, but will not be able to write to the students.

Bell-Lapadula / Biba model that is. Read more on wiki.
However, good luck, MAC is not for mortals !
Reply With Quote