FWIW, IMHO, this is a "feels good" type change. What's to stop me
writing a kernel module and running that ? (and it does all the changing
of kernel structs, calls various routines, etc)
Sure it would be nice to stop attacks based on sniffing network traffic,
but there are other solutions (such as encryption: e.g. ssh) which have
a much better effect at negating the effectiveness of those passive attacks.
Unless you have another reason for not wanting your network cards to be
able to be put into promiscious mode ?
Darren