--- Alan Cox <alan at lxorguk.ukuu.org.uk> wrote:
> Its also no magic bullet. Kernel code is considerably more of a
> security
> issue than root code especially within an SELinux framework. 

By isolating the privileged code into the driver there is much less of
it and it is much easier to inspect. The X server is a huge pile of
code that not very many people know how in detail how it all works. In
the driver model it is much easier to isolate and examine the code one
routine at a time.

