From: Pavel Machek <pavel@suse.cz>
To: Radu Filip <socrate@infoiasi.ro>
Cc: viro@parcelfarce.linux.theplanet.co.uk,
Makan Pourzandi <Makan.Pourzandi@ericsson.ca>,
Pavel Machek <pavel@suse.cz>,
linux-kernel@vger.kernel.org,
Axelle Apvrille <Axelle.Apvrille@ericsson.ca>,
Vincent Roy <vincent.roy@ericsson.ca>,
David Gordon <davidgordonca@yahoo.ca>
Subject: Re: [ANNOUNCE] DigSig 0.2: kernel module for digital signature verification for binaries
Date: Thu, 2 Oct 2003 00:05:34 +0200 [thread overview]
Message-ID: <20031001220532.GD5289@elf.ucw.cz> (raw)
In-Reply-To: <Pine.LNX.4.44.0310020043550.16234-100000@shrek.tuiasi.ro>
Hi!
> > <shrug> so in a month rootkits get updated and we are back to square 1,
> > with additional mess from patch...
>
> Viro, I think you have an attitude problem here. "Don't be ridiculous",
> "Rubbish", "<shrug>" don't sound very constructive or at least
> encouraging.
>
> Over the years it was proved that Linux kernel can be tailored for a very
> large number of unexpected and very strange needs. IBM put it into
> watches, NASA sent it to space, it is exists in oil wells and so on. I
> think that the possibilities offered by Linux kernel are limited only by
> the knowledge, imagination and will of every of us. Linux itself was once
> a very insignificant and unreliable kernel and many other serious Unix and
> Unix-like alternative were available. Still, it is prevailing today because
> some peoples believed in what they did.
>
> Especially to your point, should I mention that there are patches that
> avoid buffer-overflows? Or that there are patches for gcc that add bound
> check to arrays in C?
I simply wanted to see valid usage of this. It certainly does not
prevent attacker to get control of your box. Al seems to be right. It
may temporarily redirect script-kiddies, through...
There may be some uses like "prevent tivo users from running their own
software", but I'm not sure I want to encourage some uses. Maybe "its
neccessary to get our phones approved by FCC" would be better.
Pavel
--
When do you have a heart between your knees?
[Johanka's followup: and *two* hearts?]
next prev parent reply other threads:[~2003-10-01 22:06 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-09-25 19:19 [ANNOUNCE] DigSig 0.2: kernel module for digital signature verification for binaries Makan Pourzandi
2003-10-01 10:26 ` Pavel Machek
2003-10-01 13:33 ` Makan Pourzandi
2003-10-01 14:17 ` viro
2003-10-01 18:14 ` Makan Pourzandi
2003-10-01 18:24 ` viro
2003-10-01 21:51 ` Willy Tarreau
2003-10-01 21:55 ` Radu Filip
2003-10-01 22:05 ` Pavel Machek [this message]
2003-10-01 23:36 ` Larry McVoy
2003-10-02 0:53 ` jlnance
2003-10-02 0:17 ` [ANNOUNCE] DigSig 0.2: kernel module for digital signatureverification " Edgar Toernig
2003-10-02 2:04 ` David Gordon
2003-10-02 2:42 ` [ANNOUNCE] DigSig 0.2: kernel module for digital signature verification " Valdis.Kletnieks
2003-10-02 18:36 ` [ANNOUNCE] DigSig 0.2: kernel module for digital signature ve rification " Makan Pourzandi
2003-10-01 14:05 ` [ANNOUNCE] DigSig 0.2: kernel module for digital signature verification " Valdis.Kletnieks
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20031001220532.GD5289@elf.ucw.cz \
--to=pavel@suse.cz \
--cc=Axelle.Apvrille@ericsson.ca \
--cc=Makan.Pourzandi@ericsson.ca \
--cc=davidgordonca@yahoo.ca \
--cc=linux-kernel@vger.kernel.org \
--cc=socrate@infoiasi.ro \
--cc=vincent.roy@ericsson.ca \
--cc=viro@parcelfarce.linux.theplanet.co.uk \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.