[HN Gopher] Using Linux IMA with eBPF to protect a workload from...
___________________________________________________________________
Using Linux IMA with eBPF to protect a workload from supply chain
risk
Author : robszumski
Score : 3 points
Date : 2023-12-16 19:16 UTC (3 hours ago)
(HTM) web link (edgebit.io)
(TXT) w3m dump (edgebit.io)
| badrabbit wrote:
| I've tried implementing ima+evm. Not hard to setup but very hard
| to maintain securely. It would require distros and package
| managers to support it but every distro is still stuck in the
| 90's with their anti-pki ideology. Imagine if every system
| managed binary was cryptographically authenticated? Like macos
| and windows (well, windows has holes as always).
|
| Another issue is, IMA isn't used much so I am not confident about
| adequate security research/scrutiny having been performed to
| bypass/disable it.
___________________________________________________________________
(page generated 2023-12-16 23:01 UTC)