Re: Proposal: Remove MD5 / SHA1 support from veriexec
Sevan Janiyan <[email protected]> Sun, 27 Aug 2017 22:08:48 +0100
| Newsgroups | gmane.os.netbsd.devel.security |
|---|---|
| Message-ID | <[email protected]> |
On 08/26/17 20:30, Matthias Weckbecker wrote: > One could still boot single user mode where veriexec happens not to > be in effect, remount / rw, alter the hashes and be done with it. > > Not that I'm saying that this is necessarily a good thing, but it's > possible. Issues related to physical or console access where you're able take the machine down & boot it back up in single user mode is an entirely different discussion which is out of scope for which hash functions veriexec supports :o) Sevan