Gentoo Archives: gentoo-hardened

From: Alain Penders <alain@g.o>
To: gentoo-hardened@g.o
Subject: Re: [gentoo-hardened] Just joined, normallly would lurk, but...
Date: Tue, 11 Mar 2003 21:28:54
Message-Id: 20030311212853.GB1664@purematrix.com
In Reply to: [gentoo-hardened] Just joined, normallly would lurk, but... by lists@m8y.org
1 On Tue, Mar 11, 2003 at 04:06:58PM -0500, lists@×××.org wrote:
2 > http://www.hut.fi/~jpkarna/papers/sign.html
3 > I was wondering if anyone wanted to offer their opinion on schemes like these.
4 > Until I dug up the link and posted to /. , it was the first I'd ever heard of idea of signing executables and syscalls.
5 >
6 > Is there more info on this?
7
8 There's a whole company based around this: http://www.tripwire.com/
9
10 tripwire is a standard part of most linux distributions these days, and we're
11 looking at adding tripwire-like functionality into portage.
12
13 As for the paper... had the authors been familiar with tripwire, they might
14 have described some other security risks related to their implementation. :)
15
16 Alain
17
18 --
19 gentoo-hardened@g.o mailing list

Replies