Re: Binary only module overview

From: richard offer (offerat_private)
Date: Tue Sep 25 2001 - 07:30:38 PDT

  • Next message: richard offer: "Re: Binary only module overview"

    * frm crispinat_private "09/24/01 17:36:11 -0700" | sed '1,$s/^/* /'
    * richard offer wrote:
    *> Whats technically to stop me writing a device driver that replaces the
    *> exiting capable() code with my own implementation ? Likewise with
    *> intercepting and replacing system calls ?
    * It's an obscurity defense: make it difficult, and therefore unprofitable
    * to do so ;-)
    Must resist temptation to put forward old comment about obscurity :-)
    * Crispin
    Richard Offer                     Technical Lead, Trust Technology, SGI
    "Specialization is for insects"
    linux-security-module mailing list

    This archive was generated by hypermail 2b30 : Tue Sep 25 2001 - 07:31:28 PDT