RE: [malware-list] TALPA - a threat model? well sorta.

From: Press, Jonathan
Date: Fri Aug 15 2008 - 14:10:07 EST


> -----Original Message-----
> From: Theodore Tso [mailto:tytso@xxxxxxx]
> Sent: Friday, August 15, 2008 1:05 PM
> To: douglas.leeder@xxxxxxxxxx
> Cc: Press, Jonathan; alan@xxxxxxxxxxxxxxxxxxx; andi@xxxxxxxxxxxxxx;
Arjan van de
> Ven; hch@xxxxxxxxxxxxx; Helge Hafting; linux-kernel@xxxxxxxxxxxxxxx;
malware-
> list@xxxxxxxxxxxxxxxx; Peter Zijlstra; viro@xxxxxxxxxxxxxxxxxx
> Subject: Re: [malware-list] TALPA - a threat model? well sorta.
>
> > Not to mention removable media - it might be old hat, but
infected/malware
> > files can come in on floppies, CDs or USB flash discs careless left
on the
> > pavement outside an office.
>
> That's not a problem given the scanning model proposed by Eric; when
> you insert removable media, it will get scanned when it is first
> accessed.

That is exactly the idea. However, the context of this particular
thread was the following statement by Helge Hafting:

It seems to me that this "scan on file open" business is the
wrong
way to do things - because it reduces performance.

If you scan on file open, then your security sw is too late and
getting in the way.


We were just pointing out that this is not a good argument in practical
terms AGAINST scanning on open. In fact, your reply completely
reinforces that point.


Jon Press

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/