logoalt Hacker News

parliament32today at 2:23 PM1 replyview on HN

It's curious they're just "monitoring" rather than preventing.

In a serious environment you'd run IPE with dm-verity/fs-verity to ensure binaries are whitelisted and integrity-checked at every execution.


Replies

staticassertiontoday at 2:55 PM

lol no one does that (edit: or, rather, that is extremely uncommon, even in "serious" environments, for a ton of reasons).

show 1 reply