3 ms·
For the average linux user, key signing isn't really a big deal, imho. It isn't a big deal to the average user because os internals aren't a big deal to the av
by trotsky 14y ago
For the average linux user, key signing isn't really a big deal, imho.
It isn't a big deal to the average user because os internals aren't a big deal to the average user. Never the less, linux hasplenty of industry standard security measures like IOMMU support, DEP, ASLR, containers, RBAC, seccomp and so on.
You can't expect the average user to know what technical countermeasures they need anymore than you can expect them to know what garbage collection or interrupt coalescence strategy suits them best. It's important for folks with domain knowledge and pull requests to look out for them. The only problem in this case is the politicization rooted in hatred of a version of microsoft that differs considerably from the one that exists today.
Running as a user and protecting root without running unnecessary services is your first step, after that it's all kind of iffy.
That's advice from a different era. On the desktop (any flavor) the attack vectors are almost entirely malicious attachements, plugin exploits, browser and supporting library exploits, other random outbound clients and social engineering.
While linux isn't a popular target, it is at least as vulnerable to these attacks as the others. And due to design issues in X windows, once you can run client native code it is trivial to sniff credentials from the next elevation event.
While it's not infallibile, requiring the rootkit or bootkit to be signed by a CA raises the bar dramatically.
- qdog 14y agoI disagree that it's very political, I don't think it would be any better to designate the CA as Oracle, IBM or 37signals. If Red Hat wants to rely on msft as their CA, fine, but don't try and bring it to the kernel. I don't think running as an unprivileged user as often as possible is out of date. Yes, there are plenty of attack vectors, but there's no reason to make it easy. You could run your browser as a different user, so it can't ever see your sudo commands or whatever, just common sense. I'm not familiar with X window exploits to sniff credentials, but I would assume the application being run as a different user than the x session would add difficulty? FYI my day job is dealing with Windows, driver signing/loading issues, and what have you. I have very low expectations for the security-mindedness of average users. Many people will click on a link after an AV "warning", because "Hey, the AV will stop it if it's really an issue!"