memfd_secret() in 5.14
memfd_secret() in 5.14
Posted Aug 7, 2021 10:06 UTC (Sat) by mb (subscriber, #50428)In reply to: memfd_secret() in 5.14 by khim
Parent article: memfd_secret() in 5.14
Well, you're mixing two completely unrelated scenarios here.
I didn't base my "choice" on whether the keys are wiped from kernel memory or not.
I don't care, if there are keys in kernel memory.
But I do care, if hibernation stops working as soon as some random app starts using memfd_secret(). Yes, I know that for now that can't happen, as long as I don't enable that feature on the kernel command line. But that's exactly my point the whole time: This feature won't experience widespread use. Exactly because:
>Thus they would choose the “no security” knob 10 times out of 10.
They also will press the "more security" button 0 times out of 10.
