|
|
Log in / Subscribe / Register

Linux Kernel Security Done Right (Google Security Blog)

Linux Kernel Security Done Right (Google Security Blog)

Posted Aug 4, 2021 13:12 UTC (Wed) by jwb (guest, #15467)
In reply to: Linux Kernel Security Done Right (Google Security Blog) by smoogen
Parent article: Linux Kernel Security Done Right (Google Security Blog)

It is not the regulations themselves, but the quasi-bureaucracy of consultants and charlatans who tell companies lies about the regulations. Some guy will tell you that your company must use x.y.z to comply with FIPS 140-2, but he is lying. The convenient existence proof is google, where they maintain and release their own kernels, every week, and they have as many regulatory certifications as you can name.


to post comments

Linux Kernel Security Done Right (Google Security Blog)

Posted Aug 4, 2021 14:12 UTC (Wed) by smoogen (subscriber, #97) [Link]

It depends on the specific regulations.

Some are written so that anyone can 'meet them in the field' and others are written that you must run XYZ code as certified by ABC firm of auditors and published in DEF registry. My understanding was that if you are needing to meet the second set of certifications, you don't get the latest kernel/library set they publish.. you instead get an old set which did meet those certificates and is backported patched in a way that whatever regulation allows for.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds