|
|
Log in / Subscribe / Register

secure LSMs

secure LSMs

Posted Jul 18, 2026 11:09 UTC (Sat) by grmnsftphr (subscriber, #178591)
Parent article: Securing BPF LSMs against tampering

I'm too old by now because of seeing the same aim over and over again for the absolutely secure system (trust us, it's different this time for real!!!).

You can basically kill any system so it's of no use and then it is secure. I have seen this both in the wild as well as in-house. Who ever needs to diagnose a system on customer site with the kernel bombing? But in order to diagnose you need to keep things that LSM proponents want to kill because it conflicts work their sole aim.

Having an invisible and/or unremovable module is a sure recipe for desaster as in complex systems there will be bugs and thus a malicious actor will prevail, with no chance to remove or diagnose.

For those arguing that a malicious actor can already do this today: good you see it, but now tinkering around won't improve the situation but instead worsen it. The total debacle of user namespace design and it's many proposed band aids should have been a warning but was ignored as usual.


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds