|
|||||||||||
|
Re: security idea - bootable CD to check your system
From: <paddy(at)panici.net>
Date: Mon Jun 25 2007 - 12:20:51 EDT
I agree 100%, but ... another way of looking at it is to ask "how hard would this be to break?" There aren't any real world "known clean" kernels, just ones we can reasonably expect not to be infected by a specific problem. just like the compiler thing (reflections on trusting trust), in the real world this has ultimately underwritten by some obstacle course of tough/impossible to follow steps, such as cross-arch compiles and compiles from different compilers, and the expertise and judgment to use this, along with eyes watching for trojans in the source. A similar story no doubt applies with kernels. and then it is all to easy to assume that the underlying hardware is not a problem. but in practice being able to boot from known-clean (eg: read-only media) is a gold-standard weapon in the armoury, and anything that can help join the dots from there to "this installation is clean" is invaluable. Having a strong chain of assurance is important.
Regards,
-- To UNSUBSCRIBE, email to debian-security-REQUEST@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.orgReceived on Mon Jun 25 12:21:44 2007 This archive was generated by hypermail 2.1.8 : Mon Jun 25 2007 - 12:30:02 EDT |
||||||||||
|
|||||||||||