Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface for on access scanning

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Christoph Hellwig
Date: Monday, August 4, 2008 - 5:54 pm

On Mon, Aug 04, 2008 at 08:47:04PM -0400, Eric Paris wrote:

No, I want a sane security policy in kernelsapce that doesn't look
at the content because doing security by content properly is equivalent
to solving the halting problem.  I couldn't give a rats a** about
windows viruses as they can't actually cause any harm on a Linux
machine.


Well, data can change all the time, as can the path name.  This whole
content scanning thing doesn't make any sense at all.


So make this opt-in and in userspace.  Just LD_PRELOAD some monster lib
doing all the horrible things you propose and use it wherever you want.

--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux inte ..., Christoph Hellwig, (Mon Aug 4, 5:54 pm)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linux inte ..., David Collier-Brown, (Wed Aug 6, 4:31 am)
Sidebar to [malware-list] [RFC 0/5] [TALPA] Intro to a lin ..., David Collier-Brown, (Wed Aug 6, 4:40 am)
Re: [malware-list] [RFC 0/5] [TALPA] Intro to a linuxinter ..., David Collier-Brown, (Mon Aug 11, 9:11 am)