Re: [RFC] Second attempt at kernel secure boot support

From: Jiri Kosina
Date: Thu Nov 01 2012 - 05:45:39 EST


On Thu, 1 Nov 2012, James Bottomley wrote:

> I'm actually just struggling to understand the use case for these more
> esoteric protections.

I believe the real point is drawing a clear line between trusted and
untrusted (with root being userspace, hence implicitly untrusted), and
disallowing "legitimate crossing" of this line.

--
Jiri Kosina
SUSE Labs
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/