To: Theodore Tso <tytso@...>, <douglas.leeder@...>
Cc: <alan@...>, <andi@...>, Arjan van de Ven <arjan@...>, <hch@...>, Helge Hafting <helge.hafting@...>, <linux-kernel@...>, <malware-list@...>, Peter Zijlstra <peterz@...>, <viro@...>
Arjan van de
malware-
infected/malware
on the
That is exactly the idea. However, the context of this particular
thread was the following statement by Helge Hafting:
It seems to me that this "scan on file open" business is the
wrong
way to do things - because it reduces performance.
If you scan on file open, then your security sw is too late and
getting in the way.
We were just pointing out that this is not a good argument in practical
terms AGAINST scanning on open. In fact, your reply completely
reinforces that point.
Jon Press
--