make /boot and /lib/modules unreadable even for root

Information

ID: 943
PHID: PHID-TASK-ikdtkehxadknzfoo7keb
Author: Patrick
Status at Migration Time: resolved
Priority at Migration Time: Normal

Description

Similar to T937 but this is for defense in depth and even preventing root from getting access to kernel symbols.

Comments


madaidan

2019-12-23 20:27:00 UTC


Patrick

2019-12-24 11:17:33 UTC


madaidan

2019-12-24 15:37:16 UTC


Patrick

2019-12-24 15:49:02 UTC


madaidan

2019-12-24 16:07:30 UTC