[HN Gopher] Using Linux IMA with eBPF to protect a workload from...
       ___________________________________________________________________
        
       Using Linux IMA with eBPF to protect a workload from supply chain
       risk
        
       Author : robszumski
       Score  : 3 points
       Date   : 2023-12-16 19:16 UTC (3 hours ago)
        
 (HTM) web link (edgebit.io)
 (TXT) w3m dump (edgebit.io)
        
       | badrabbit wrote:
       | I've tried implementing ima+evm. Not hard to setup but very hard
       | to maintain securely. It would require distros and package
       | managers to support it but every distro is still stuck in the
       | 90's with their anti-pki ideology. Imagine if every system
       | managed binary was cryptographically authenticated? Like macos
       | and windows (well, windows has holes as always).
       | 
       | Another issue is, IMA isn't used much so I am not confident about
       | adequate security research/scrutiny having been performed to
       | bypass/disable it.
        
       ___________________________________________________________________
       (page generated 2023-12-16 23:01 UTC)