Corgi Lemmings
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@lemmy.world to Linux@programming.dev · 2 months ago

Microsoft Proposes "Hornet" Security Module For The Linux Kernel

lore.kernel.org

external-link
message-square
16
fedilink
  • cross-posted to:
  • [email protected]
72
external-link

Microsoft Proposes "Hornet" Security Module For The Linux Kernel

lore.kernel.org

cm0002@lemmy.world to Linux@programming.dev · 2 months ago
message-square
16
fedilink
  • cross-posted to:
  • [email protected]
[RFC PATCH security-next 0/4] Introducing Hornet LSM
lore.kernel.org
external-link

https://www.phoronix.com/news/Microsoft-Hornet-Linux-LSM

alert-triangle
You must log in or register to comment.
  • macniel@feddit.org
    link
    fedilink
    arrow-up
    46
    ·
    2 months ago

    I dunno about this one chief; call it Microsoft paranoia.

    • prettybunnys@sh.itjust.works
      link
      fedilink
      arrow-up
      6
      ·
      2 months ago

      One of the better security modules in the kernel was developed by the NSA.

      It’s open source software and Microsoft can’t force it in, the open source model will handle this properly.

      • macniel@feddit.org
        link
        fedilink
        arrow-up
        2
        ·
        2 months ago

        Okay well, It wouldn’t have been the first code blob in the kernel (looking at you HDMI)

  • Maki@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    45
    arrow-down
    1
    ·
    edit-2
    2 months ago

    How about no? The whole proposal looks shady. Where Microsoft says “trust”, I do not.

  • 1984@lemmy.today
    link
    fedilink
    arrow-up
    32
    arrow-down
    6
    ·
    2 months ago

    Every Microsoft idea is always bad for Linux.

  • katy ✨@lemmy.blahaj.zone
    cake
    link
    fedilink
    arrow-up
    17
    arrow-down
    1
    ·
    2 months ago

    it’s a trap

  • zero_spelled_with_an_ecks@programming.dev
    link
    fedilink
    arrow-up
    11
    ·
    2 months ago

    Oh geeze, that format drives me nuts. Is there a tldr?

    • hellofriend@lemmy.world
      link
      fedilink
      arrow-up
      11
      arrow-down
      4
      ·
      2 months ago

      Amigo, it’s 5 paragraphs and two of those are a quote.

      • zero_spelled_with_an_ecks@programming.dev
        link
        fedilink
        arrow-up
        14
        ·
        2 months ago

        Oh, there’s two different links, the kernel lore one is the one I was complaining about.

        • hellofriend@lemmy.world
          link
          fedilink
          arrow-up
          9
          ·
          2 months ago

          Oh, I didn’t think to check. Figured they were the same. But yeah, looking at it now it looks rather horrible, doesn’t it?

    • Kairos@lemmy.today
      link
      fedilink
      arrow-up
      5
      ·
      2 months ago
      This adds the Hornet Linux Security Module which provides signature
      verification of eBPF programs.
      
  • Colonel Panic@programming.dev
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    edit-2
    2 months ago

    did we arrive at the second stage of embrace, extend, extinguish?

    • prettybunnys@sh.itjust.works
      link
      fedilink
      arrow-up
      3
      ·
      edit-2
      2 months ago

      No, Microsoft would likely sooner fully adopt the Linux kernel tbh.

      It aligns with their software/service as a service model.

      My bet is you’ll see a “windows 11” compatible user space running on Linux a la WSL ( LSW? ) in the coming decade.

      I know Linux engineers who moved to Microsoft generally for this purpose

      • Colonel Panic@programming.dev
        link
        fedilink
        arrow-up
        2
        arrow-down
        1
        ·
        2 months ago

        that’s how the “extinguish” phase start - integrate it closely into your own product, so people use yours instead

  • vermaterc@lemmy.ml
    link
    fedilink
    arrow-up
    6
    ·
    2 months ago

    Can anyone ELI5 why it’s bad? Apart from contributior being Microsoft

  • henfredemars@infosec.pub
    link
    fedilink
    English
    arrow-up
    7
    arrow-down
    2
    ·
    2 months ago

    Very interesting. I’m sure it will find some consumers for this code, in systems that use codesign.

Linux@programming.dev

linux@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community for everything relating to the GNU/Linux operating system

Also check out:

  • [email protected]
  • [email protected]

Original icon base courtesy of [email protected] and The GIMP

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 338 users / day
  • 1.54K users / week
  • 4.4K users / month
  • 7.19K users / 6 months
  • 1 local subscriber
  • 7.26K subscribers
  • 1.53K Posts
  • 11.9K Comments
  • Modlog
  • mods:
  • Ategon@programming.dev
  • adr1an@programming.dev
  • dwraf_of_ignorance@programming.dev
  • BE: 0.19.8
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org