[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Challenge to you: Voice your concerns regarding systemd upstream



green wrote at 2014-09-26 21:04 -0500:
> Ric Moore wrote at 2014-09-26 18:08 -0500:
> > On 09/26/2014 05:08 PM, green wrote:
> > >So, all other things being equal, binary logs are more secure than
> > >plain text logs.  Is that actually what you are saying?
> > 
> > Yes. The benefit of using a binary log is the lesser vulnerability to an
> > external attack from an intruder. That huge security flaw was mentioned on a
> > recent PBS video regarding the new day Hackers and how simply they
> > removed/edited text-log files to hide their tracks of what they did.
> 
> So now the attacker just destroys all the logs instead, because it is
> easier than editing the binary.

Hm, if you are concerned about the validity of your server logs, it
might be prudent to read #10 at
http://judecnelson.blogspot.fi/2014/09/systemd-biggest-fallacies.html

Attachment: signature.asc
Description: Digital signature


Reply to: