|
From: Friedrich L. <fl...@fl...> - 2004-02-08 20:19:06
|
Heiko Zuerker wrote on 08.02.2004 20:50 MET: > Friedrich Lobenstock wrote: > >> Heiko Zuerker wrote on 08.02.2004 16:21 MET: >> >>> The major problem is that it's easy to temper with the verification >>> of the signature, by replacing the initrd on the memory stick. >> >> Then initrd needs to check its own signature first. If this does not >> check out - hold the damned thing so the users _has to_ manually >> intervene. > > > That's the way I'm gonna do it, when we don't find a better solution. > This means that we have to trust that the system is secure, which I > don't really like. > The main problem is that when somebody gains access to the host, he can > replace the initrd, without any problems, with his own version... Hmmmm.....what's this stuff M$ and the music industry wants in our PCs?... -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |