Scanning on open should be a last resort. Scan in advance when you can.-----Original Message-----Arjan van de
From: Theodore Tso [mailto:tytso@xxxxxxx]
Sent: Friday, August 15, 2008 1:05 PM
To: douglas.leeder@xxxxxxxxxx
Cc: Press, Jonathan; alan@xxxxxxxxxxxxxxxxxxx; andi@xxxxxxxxxxxxxx;
Ven; hch@xxxxxxxxxxxxx; Helge Hafting; linux-kernel@xxxxxxxxxxxxxxx;malware-
list@xxxxxxxxxxxxxxxx; Peter Zijlstra; viro@xxxxxxxxxxxxxxxxxxinfected/malware
Subject: Re: [malware-list] TALPA - a threat model? well sorta.
Not to mention removable media - it might be old hat, but
on thefiles can come in on floppies, CDs or USB flash discs careless left
pavement outside an office.That's not a problem given the scanning model proposed by Eric; when
you insert removable media, it will get scanned when it is first
accessed.
That is exactly the idea. However, the context of this particular
thread was the following statement by Helge Hafting:
It seems to me that this "scan on file open" business is the
wrong way to do things - because it reduces performance.
If you scan on file open, then your security sw is too late and getting in the way.
We were just pointing out that this is not a good argument in practical
terms AGAINST scanning on open. In fact, your reply completely
reinforces that point.