1 |
On Tue, Mar 11, 2003 at 04:06:58PM -0500, lists@×××.org wrote: |
2 |
> http://www.hut.fi/~jpkarna/papers/sign.html |
3 |
> I was wondering if anyone wanted to offer their opinion on schemes like these. |
4 |
> Until I dug up the link and posted to /. , it was the first I'd ever heard of idea of signing executables and syscalls. |
5 |
> |
6 |
> Is there more info on this? |
7 |
|
8 |
There's a whole company based around this: http://www.tripwire.com/ |
9 |
|
10 |
tripwire is a standard part of most linux distributions these days, and we're |
11 |
looking at adding tripwire-like functionality into portage. |
12 |
|
13 |
As for the paper... had the authors been familiar with tripwire, they might |
14 |
have described some other security risks related to their implementation. :) |
15 |
|
16 |
Alain |
17 |
|
18 |
-- |
19 |
gentoo-hardened@g.o mailing list |