Why is DAC inadequate?
-
Decisions are only based on user identity and ownership
-
No protection against malicious or flawed software
-
Each user has complete discretion over his objects
-
Only two major categories of users: administrator and
other
-
Many system services and privileged programs must run with
coarse-grained privileges or even full administrator access.