lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <alpine.DEB.1.10.0811302121070.835@asgard.lang.hm>
Date:	Sun, 30 Nov 2008 21:22:17 -0800 (PST)
From:	david@...g.hm
To:	Enrico Weigelt <weigelt@...ux.de>
cc:	linux kernel list <linux-kernel@...r.kernel.org>
Subject: Re: scanner interface proposal was: [TALPA] Intro to a linux interface
 for on access scanning (fwd)

On Mon, 1 Dec 2008, Enrico Weigelt wrote:

> * Alan Cox <alan@...rguk.ukuu.org.uk> wrote:
>>> Fine. Why not just putting this into a userland filesystem ?
>>
>> 1. Performance
>
> Does it really hurt so bad, compared with all actual AV stuff ?
> It has to go to userland anyway, in case you don't intend to
> put the scanner into the kernel ;-o

if you have to scan every file then you are right, the userland overhead 
would be swamped by the scanner overhead. but much of the time you will be 
accessing files that are already scanned or that you aren't going to scan, 
but you would still be paying the userland penalty for the filesystem.

David Lang

>> 2. Networked file systems
>
> What's the problem ?
> (btw: 9P already *IS* an network filesystem ;-P)
>
>> 3. Ioctls
>
> Ah, just forgot a while that this crap still exists ;-o
>
> BUT: do the affected dirs have to contain devices ?
> Is there any point for pulling /dev through the AV scanner ?
>
>
> cu
>
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ