AppArmor & SELinux Explained
AppArmor and SELinux put a mandatory policy in the kernel, underneath the normal Unix permissions every admin already knows. They are quietly excellent — right up to the moment someone flips a process into complain mode, sets the box permissive “just to test,” or pastes an over-broad audit2allow rule. Then the guard is still standing at the door, badge on, writing nothing down.
Members Only Content
This article is exclusively available to premium members of LazyHackers. Login or subscribe to read.