Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753731AbYHROZn (ORCPT ); Mon, 18 Aug 2008 10:25:43 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1752623AbYHROZd (ORCPT ); Mon, 18 Aug 2008 10:25:33 -0400 Received: from www.church-of-our-saviour.ORG ([69.25.196.31]:51519 "EHLO thunker.thunk.org" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752530AbYHROZc (ORCPT ); Mon, 18 Aug 2008 10:25:32 -0400 Date: Mon, 18 Aug 2008 10:25:11 -0400 From: Theodore Tso To: tvrtko.ursulin@sophos.com Cc: david@lang.hm, davecb@sun.com, Adrian Bunk , Peter Dolding , rmeijer@xs4all.nl, Mihai Don??u , linux-kernel , malware-list@lists.printk.net, linux-security-module@vger.kernel.org, malware-list-bounces@dmesg.printk.net, Casey Schaufler , Pavel Machek , capibara@xs4all.nl, Alan Cox , Arjan van de Ven Subject: Re: [malware-list] scanner interface proposal was: [TALPA] Intro to a linux interface for on access scanning Message-ID: <20080818142511.GC8184@mit.edu> Mail-Followup-To: Theodore Tso , tvrtko.ursulin@sophos.com, david@lang.hm, davecb@sun.com, Adrian Bunk , Peter Dolding , rmeijer@xs4all.nl, Mihai Don??u , linux-kernel , malware-list@lists.printk.net, linux-security-module@vger.kernel.org, malware-list-bounces@dmesg.printk.net, Casey Schaufler , Pavel Machek , capibara@xs4all.nl, Alan Cox , Arjan van de Ven References: <20080818131628.1C2A22FE82F@pmx1.sophos.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20080818131628.1C2A22FE82F@pmx1.sophos.com> User-Agent: Mutt/1.5.17+20080114 (2008-01-14) X-SA-Exim-Connect-IP: X-SA-Exim-Mail-From: tytso@mit.edu X-SA-Exim-Scanned: No (on thunker.thunk.org); SAEximRunCond expanded to false Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1034 Lines: 20 On Mon, Aug 18, 2008 at 02:15:24PM +0100, tvrtko.ursulin@sophos.com wrote: > Then there is still a question of who allows some binary to declare itself > exempt. If that decision was a mistake, or it gets compromised security > will be off. A very powerful mechanism which must not be easily > accessible. With a good cache your worries go away even without a scheme > like this. I have one word for you --- bittorrent. If you are downloading a very large torrent (say approximately a gigabyte), and it contains many pdf's that are say a few megabytes a piece, and things are coming in tribbles, having either a indexing scanner or an AV scanner wake up and rescan the file from scratch each time a tiny piece of the pdf comes in is going to eat your machine alive.... - Ted -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/