[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20091112175242.135366aa@lxorguk.ukuu.org.uk>
Date: Thu, 12 Nov 2009 17:52:42 +0000
From: Alan Cox <alan@...rguk.ukuu.org.uk>
To: "Henrique de Moraes Holschuh" <hmh@....eng.br>
Cc: "Robert Hancock" <hancockrwd@...il.com>,
"Anton D. Kachalov" <mouse@...c.ru>, linux-kernel@...r.kernel.org
Subject: Re: Reading /dev/mem by dd
> > Any forensics person who images /dev/mem needs to go back to school.
>
> While I do agree with you, I can assure you they do it all the time at
> least around here, and it is still listed as "best practice" in the
> notebooks of many.
Oh dear me. Well the purpose of the kernel isn't to provide an idiot
filter, that is what the security policies and not giving people root is
for.
You have a people problem. Technical fixes to people problems rarely work.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/
Powered by blists - more mailing lists