[LBo] [Opinion] Critical Linux security API is still a kludge

Floris Kraak randakar at gmail.com
Tue Oct 24 09:20:02 CEST 2006


On 10/24/06, Sam Morgan <s.morgan at linuxbasics.org> wrote:
>
> "The talk lately has centered about Vista's security APIs, but Linux certainly
> needs improvements in this area, because AV vendors still rely on an external
> kernel module to implement 'real time' file scanning..."

It's funny. Linux doesn't have viruses*, but the antivirus vendors
still need a kernel API for their scanning modules. 'Why' is a matter
I leave to the observer.

As for their whining about needing an external module, it's really
extraordinarily simple. You want code in the kernel? Fine, then work
with the kernel community. Write an GPL'ed kernel module and submit it
for inclusion.
Getting code in the kernel may be a rough process but your code will
be better for it, and everyone wins.

In other words, imho the antivirus vendors complaint should be
directed at themselves.


*) Or at least, no viruses that actually pose a threat to anyone..

-- 
"Rarely do we find men who willingly engage in hard, solid thinking.
There is an almost universal quest for easy answers and half-baked
solutions. Nothing pains some people more than having to think."
  - Martin Luther King


More information about the QnA mailing list