A: No.
Q: Should I include quotations after my reply?
On Tue, Aug 05, 2008 at 02:04:26PM -0400, Press, Jonathan wrote:
I think you might be missing the point a bit here, as the traditional
Unix model that Linux has prevents much of what the "traditional AV"
products need to do, right?
Great, then put a hook in glibc and catch all closes and then kick off
your scanning.
But this proposed patchset does not do much to prevent all of these,
right?
So how are you going about preventing the "infection from arriving"
with this proposed patchset?
Isn't that something that SELinux or another LSM can prevent better?
thanks,
greg k-h
--