Github messages for voidlinux
 help / color / mirror / Atom feed
From: ericonr <ericonr@users.noreply.github.com>
To: ml@inbox.vuxu.org
Subject: Re: [RFC] signed kernel modules
Date: Thu, 07 Jan 2021 15:29:18 +0100	[thread overview]
Message-ID: <20210107142918.cSel8XnGOVjTRSqCh1v3zL0L-vsKmw_kr-kAphEjEOU@z> (raw)
In-Reply-To: <gh-mailinglist-notifications-41a7ca26-5023-4802-975b-f1789d68868e-void-packages-27736@inbox.vuxu.org>

[-- Attachment #1: Type: text/plain, Size: 716 bytes --]

New comment by ericonr on void-packages repository

https://github.com/void-linux/void-packages/issues/27736#issuecomment-756150464

Comment:
I don't see what advantage this brings, since an attacker who has access to the kernel modules could just as well change programs, libraries, or possibly even the kernel itself, making any signing moot.

Furthermore, given that a lot of people might end up requiring one DKMS module or another (nvidia, zfs, ...), this would only be useful if they self built their own kernel with a custom config pointing to the additional key. And then they'd have to set up the whole infrastructure around actually signing the modules and such, plus somehow protect the key adequately.

  reply	other threads:[~2021-01-07 14:29 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-01-07 10:29 [ISSUE] " dkwo
2021-01-07 14:29 ` ericonr [this message]
2021-01-07 20:26 ` ahesford
2021-01-14  6:58 ` fosslinux
2021-01-16 15:46 ` dkwo
2021-01-16 15:46 ` [ISSUE] [CLOSED] " dkwo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20210107142918.cSel8XnGOVjTRSqCh1v3zL0L-vsKmw_kr-kAphEjEOU@z \
    --to=ericonr@users.noreply.github.com \
    --cc=ml@inbox.vuxu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).