oss-sec mailing list archives
Re: IMA gadgets
From: Johannes Segitz <jsegitz () suse de>
Date: Wed, 1 Dec 2021 09:06:33 +0100
On Tue, Nov 30, 2021 at 09:16:20PM +0100, Florian Weimer wrote:
So in short, I don't really see how IMA signatures shipped as part of all distribution packages, on all files, can provide value beyond that of the hash that the already contain.
It provides "the customer is happy" value. From a security POV it doesn't help much (on a normal Linux system, can be different if you really strip it down). But AMSI also doesn't help and people are still keen on enabling it, despite bypasses being available all the time. Same will happen for IMA. Johannes -- GPG Key EE16 6BCE AD56 E034 BFB3 3ADD 7BF7 29D5 E7C8 1FA0 Subkey fingerprint: 250F 43F5 F7CE 6F1E 9C59 4F95 BC27 DD9D 2CC4 FD66 SUSE Software Solutions Germany GmbH, Maxfeldstr. 5, 90409 Nuernberg Geschäftsführer: Ivo Totev (HRB 36809, AG Nürnberg)
Attachment:
signature.asc
Description: Digital signature
Current thread:
- IMA gadgets Florian Weimer (Nov 30)
- Re: IMA gadgets Grant Taylor (Dec 01)
- Re: IMA gadgets Jens Timmerman (Dec 01)
- Re: IMA gadgets Johannes Segitz (Dec 01)
- Re: IMA gadgets Travis Finkenauer (Dec 01)
- Re: IMA gadgets Grant Taylor (Dec 01)