Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This is fantastic, a few navie questions though:

1. Why not find some permanently-read-only media for the boot drive and then not have to be so paranoid about its physical integrity?

2. Why not leverage the PGP smart card for more things like signin via PAM, etc?

3. Will Wayland help keep processes isolated from an eavesdropping perspective? My understanding is that, worse than firefox having access to your user files, that any X window can read/write from other X windows?



With the read-only media you've got a problem with upgrading the kernel, which, recently, you need to be doing quite often.

As for the PGP smartcard, I've posted a comment on the blog that it could hold the private key used for decrypting the keyfile for the Full-Disk Encryption.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: