lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: Tue, 14 Nov 2017 09:34:29 -0800 From: Linus Torvalds <torvalds@...ux-foundation.org> To: Mimi Zohar <zohar@...ux.vnet.ibm.com> Cc: David Howells <dhowells@...hat.com>, Alan Cox <gnomes@...rguk.ukuu.org.uk>, "Luis R. Rodriguez" <mcgrof@...nel.org>, "AKASHI, Takahiro" <takahiro.akashi@...aro.org>, Greg Kroah-Hartman <gregkh@...uxfoundation.org>, Jan Blunck <jblunck@...radead.org>, Julia Lawall <julia.lawall@...6.fr>, Marcus Meissner <meissner@...e.de>, Gary Lin <GLin@...e.com>, LSM List <linux-security-module@...r.kernel.org>, linux-efi <linux-efi@...r.kernel.org>, Linux Kernel Mailing List <linux-kernel@...r.kernel.org>, Matthew Garrett <mjg59@...gle.com> Subject: Re: Firmware signing -- Re: [PATCH 00/27] security, efi: Add kernel lockdown On Tue, Nov 14, 2017 at 4:21 AM, Mimi Zohar <zohar@...ux.vnet.ibm.com> wrote: > On Mon, 2017-11-13 at 14:09 -0800, Linus Torvalds wrote: >> >> Seriously, if you have firmware in /lib/firmware, and you don't trust >> it, what the hell are you doing? > > I might "trust" the files in /lib/firmware, but I also want to make > sure that they haven't changed. File signatures provide file > provenance and integrity guarantees. Sure. But that has absolutely nothing to do with "firmware". It is equally true of /usr/bin/* and pretty much everything in the system. It's this insane "firmware is special" that I disagree with. It's not special at all. Linus
Powered by blists - more mailing lists