> On 5 Sep 2008 at 13:42, Ingo Molnar wrote:
> > The other, more fundamental problem that nobody has mentioned so far is
> > that the check returns -ENOSYS and thus makes rootkit attacks _more
> > robust_ and hence more likely!
> >
> > The far better solution would be to insert uncertainty into the
> > picture: some sort of low-frequency watchdog [runs once a second or
> > so] that tries to hide itself from the general kernel scope as much
> > as possible, perhaps as ELF-PIC code at some randomized location,
> > triggered by some frequently used and opaque kernel facility that an
> > attacker can not afford to block or fully filter, and which would
> > just check integrity periodically and with little cost.
>
> there's that adage about history being repeated by those not knowing it ;)
> for details see the series based around bypassing Vista's PatchGuard at:
>
>
http://uninformed.org/?v=3
>
http://uninformed.org/?v=6
>
http://uninformed.org/?v=8