Re: Proposal: Remove MD5 / SHA1 support from veriexec

Matthias Weckbecker <[email protected]> Sat, 26 Aug 2017 21:30:01 +0200
Newsgroups gmane.os.netbsd.devel.security
Message-ID <20170826213001.396cac91@silentmaxx>
On Tue, 22 Aug 2017 15:35:57 +0930
Brett Lymn <[email protected]> wrote:

[...]
> You don't have to up the strict level on veriexec, that way it won't
> block execs but, yes, it would not be good if you cannot boot a new
> kernel.
> 

One could still boot single user mode where veriexec happens not to
be in effect, remount / rw, alter the hashes and be done with it.

Not that I'm saying that this is necessarily a good thing, but it's
possible.

Matthias