On Tue, Aug 05, 2008 at 01:38:32PM -0700, Arjan van de Ven wrote:Actually, the real question (and the reason why I question the personal integrity of the people in "AV community" pushing that kind of trash) is very simple: Where Is Your Threat Profile? Various people had been asking for _years_ to define what the hell are you trying to prevent. Not only there'd been no coherent answer (and no, this list of requirements is _not_ that - it's "what kind of hooks do we want"), you guys seem to be unable to decide whether you expect the malware in question to be passive or to be actively evading detection with infected processes running on the host that does scanning. Moreover, the answer seems to be changing back and forth to suit the needs of the moment in the argument. Slightly exaggregated it goes like this: -- Why don't you do $FOO? -- Running virus would be able to evade $FOO, of course! -- No shit, Sherlock; it would also be able to evade much more intrusive $BAR you are proposing; here's how <obvious evasion method> -- Oh, but that's not a problem; think of Linux server with Windows clients and Windows viruses... --
| Ingo Molnar | Re: x86: 4kstacks default |
| Gabriel C | modpost errors ( Re: 2.6.23-rc6-mm1) |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
| Press, Jonathan | RE: [malware-list] [RFC 0/5] [TALPA] Intro to a linux interface foron access scann... |
git: | |
| David Miller | Re: iptables very slow after commit784544739a25c30637397ace5489eeb6e15d7d49 |
| Natalie Protasevich | [BUG] New Kernel Bugs |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 13/37] dccp: Deprecate Ack Ratio sysctl |
