1. Keep the kernel image on non-writable media as well.
2. If the kernel is compromised, then kernel-level protection doesn't help
you either (the above was a reference to the claim that user-level daemons
couldn't be trusted). You're screwed unless your defense is implemented
in hardware (which is basically equivalent to putting the kernel and
security daemons on non-writable media).
-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.rutgers.edu
Please read the FAQ at http://www.tux.org/lkml/