178
submitted 11 months ago* (last edited 11 months ago) by tomenzgg@midwest.social to c/linux@programming.dev
you are viewing a single comment's thread
view the rest of the comments
[-] quick_snail@feddit.nl 2 points 11 months ago

AV is a joke. Best thing is ephemerality. No persistence

[-] fruitycoder@sh.itjust.works 6 points 11 months ago

Immutable, ephemerable, granularly permissioned, and encrypt EVERYTHING to enforce said permissions.

1000x better than software signature hunting

[-] quick_snail@feddit.nl 3 points 11 months ago

You lost me at the encryption part. How does encrypting enforce permissions?

[-] fruitycoder@sh.itjust.works 2 points 11 months ago

Enforces confidentiality and integrity.

Encryption on transports protects from man in the middle and sniffing. At rest protects evil maid exploits, which for these systems is more about preventing malicious software being swapped in place of trusted software.

The same applies to encryption of links like pcie and memory with the time of transport and rest changing.

[-] rumba@lemmy.zip 2 points 11 months ago

It's all fun and games until some asshole slips something into your trusted package manager.

Exploits are the deal pain

[-] fruitycoder@sh.itjust.works 1 points 11 months ago

Yep SLSA is more than just a trusted end point. Package signatures, reproducible builds, SBOMs, signed commits and more!

this post was submitted on 27 Oct 2025
178 points (93.2% liked)

Linux

15124 readers
643 users here now

A community for everything relating to the GNU/Linux operating system (except the memes!)

Also, check out:

Original icon base courtesy of lewing@isc.tamu.edu and The GIMP

founded 3 years ago
MODERATORS