Re: veriexec in OpenBSD?

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Kenneth Gober
Date: Wednesday, September 1, 2010 - 2:24 pm

On Wed, Sep 1, 2010 at 4:14 PM, Milin <merlyn500@gmail.com> wrote:


it looks like an interesting idea, but I'm not sure what vulnerability it
protects you from.  if you don't want users to replace system files, it
seems like a better idea to prevent them from being replaced, rather than
allowing replacement but then preventing access.

not that the 'preventing access' problem is much of an obstacle.  the
article I found via google didn't have a lot of details, but it seems like
if you have rights to replace the files, you probably also have rights to
write an updated signature to /dev/veriexec.  if you're not going to require
the signatures to themselves be signed I really don't see the point.

still, if some developer were interested enough to write a diff, there's
nothing stopping them.

-ken
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
veriexec in OpenBSD?, Milin, (Wed Sep 1, 1:14 pm)
Re: veriexec in OpenBSD?, Ted Unangst, (Wed Sep 1, 2:11 pm)
Re: veriexec in OpenBSD?, Kenneth Gober, (Wed Sep 1, 2:24 pm)
Re: veriexec in OpenBSD?, Brett Lymn, (Wed Sep 1, 6:58 pm)