4 ms·
"You could even spawn a process to remove the pam_duress module so the threat actor won't be able to see if the duress module was available" This scenario was
by muti 5y ago
"You could even spawn a process to remove the pam_duress module so the threat actor won't be able to see if the duress module was available"
This scenario was considered by the author
- yosito 5y agoAh, thanks! I didn't read closely enough.
- Nextgrid 5y agoTechnically you'd also need to rewrite the logs in a plausible manner (removing the mentions of the PAM module and potentially replacing it with their "normal" equivalents) and depending on your threat model, actually securely erase the files so that disk recovery software can't later restore the deleted files.
- Sebb767 5y agoIf your threat model is someone that will even invest the time to sift through your logs, it might be wise to disable (persistent) logging in the first place.