logoalt Hacker News

bananapubyesterday at 10:51 AM0 repliesview on HN

immutable is a handy advisory feature, but the actual answer for log tampering is "get them off the box in to a different security domain", e.g. a log server this machine can't access and is securely backed up so logs that make it there can be fairly well trusted.