Subject: Re: Preventative security features?
To: Tim Kelly <hockey@dialectronics.com>
From: Brett Lymn <blymn@baesystems.com.au>
List: tech-security
Date: 11/15/2004 13:59:04
On Sun, Nov 14, 2004 at 10:05:09PM -0500, Tim Kelly wrote:
> 
> How does it deal with self-modifying code as one might see in a buffer
> overflow? 

It doesn't.  Buffer overflows is not what it's about - it's more about
making sure you can have a TCB.

>Is the fingerprint only valid up to the point the image is
> loaded into memory?
> 

Yes.

> 
> I'd offer to help, but my hands are full squashing bugs on macppc. Since
> it isn't available across ports, can it be justified as a default option
> in the kernel?
> 

Not default in kernel - there is a special kernel config you need to
use.

-- 
Brett Lymn