Re: Proposal: Remove MD5 / SHA1 support from veriexec

Sevan Janiyan <[email protected]> Sun, 27 Aug 2017 22:08:48 +0100
Newsgroups gmane.os.netbsd.devel.security
Message-ID <[email protected]>

On 08/26/17 20:30, Matthias Weckbecker wrote:
> One could still boot single user mode where veriexec happens not to
> be in effect, remount / rw, alter the hashes and be done with it.
> 
> Not that I'm saying that this is necessarily a good thing, but it's
> possible.

Issues related to physical or console access where you're able take the
machine down & boot it back up in single user mode is an entirely
different discussion which is out of scope for which hash functions
veriexec supports :o)


Sevan