Re: LSM conversion to static interface

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Giacomo Catenazzi <cate@...>
Cc: Thomas Fricaccia <thomas_fricacci@...>, <linux-kernel@...>, Alan Cox <alan@...>, Linus Torvalds <torvalds@...>, Greg KH <greg@...>, LSM ML <linux-security-module@...>
Date: Tuesday, October 23, 2007 - 3:12 am

Giacomo Catenazzi wrote:
*I* understand that, from a security and logic integrity point of view,
there is not much difference between a rebuilt-from-source kernel, and a
standard kernel from the distro with a new module loaded.

However, there is a big difference for other people, depending on their
circumstances.

    * Some people live in organizations where the stock kernel is
      required, even if you are allowed to load modules. That may not
      make sense to you, but that doesn't change the rule.
    * Some people are not comfortable building kernels from source. It
      doesn't matter how easy *you* think it is, it is a significant
      barrier to entry for a lot of people. Especially if their day job
      is systems or security administration, and not kernel hacking.

Think of it like device drivers: Linux would be an enterprise failure if
you had to re-compile the kernel from source every time you added a new
kind of device and device driver.

Crispin

-- 
Crispin Cowan, Ph.D.               http://crispincowan.com/~crispin/
	       Itanium. Vista. GPLv3. Complexity at work

-
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: LSM conversion to static interface, Thomas Fricaccia, (Mon Oct 22, 1:00 pm)
Re: LSM conversion to static interface, Giacomo Catenazzi, (Tue Oct 23, 1:53 am)
Re: LSM conversion to static interface, Crispin Cowan, (Tue Oct 23, 3:12 am)
Re: LSM conversion to static interface, Greg KH, (Tue Oct 23, 11:41 pm)
Re: LSM conversion to static interface, Giacomo A. Catenazzi, (Tue Oct 23, 4:17 am)
Re: LSM conversion to static interface, Greg KH, (Mon Oct 22, 1:13 pm)
Re: LSM conversion to static interface, Simon Arlott, (Tue Oct 23, 7:38 am)
Re: LSM conversion to static interface, Crispin Cowan, (Tue Oct 23, 1:14 am)
Re: LSM conversion to static interface, Alan Cox, (Mon Oct 22, 1:12 pm)