惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 三生石上(FineUI控件)
T
Threat Research - Cisco Blogs
月光博客
月光博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
爱范儿
爱范儿
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
云风的 BLOG
云风的 BLOG
D
Docker
罗磊的独立博客
U
Unit 42
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
P
Proofpoint News Feed
博客园 - Franky
Apple Machine Learning Research
Apple Machine Learning Research
MyScale Blog
MyScale Blog
B
Blog RSS Feed
美团技术团队
J
Java Code Geeks
S
Securelist
Cyberwarzone
Cyberwarzone
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
NISL@THU
NISL@THU
Security Latest
Security Latest
Recent Commits to openclaw:main
Recent Commits to openclaw:main
Recorded Future
Recorded Future
Hacker News - Newest:
Hacker News - Newest: "LLM"
L
LINUX DO - 热门话题
Recent Announcements
Recent Announcements
Last Week in AI
Last Week in AI
A
About on SuperTechFans
MongoDB | Blog
MongoDB | Blog
Spread Privacy
Spread Privacy
T
Tenable Blog
I
Intezer
N
News | PayPal Newsroom
大猫的无限游戏
大猫的无限游戏
A
Arctic Wolf
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX - 技术
S
Schneier on Security
S
SegmentFault 最新的问题
Latest news
Latest news
宝玉的分享
宝玉的分享
V
Visual Studio Blog
V
V2EX
T
Tor Project blog
C
Comments on: Blog

LWN.net comments

Support for block sizes larger than the page size as one unit [LWN.net] Escalating from root to kernel [LWN.net] There's AI slop and anti-AI slop [LWN.net] Escalating from root to kernel [LWN.net] There's AI slop and anti-AI slop [LWN.net] Coming from Debian [LWN.net] Escalating from root to kernel [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] Understandability [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] became clear how? [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] Incorrect dataset licenses in MOT [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] Second-class fs [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] Scraper traffic [LWN.net] ditto sorta [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] If this actually works... [LWN.net] If this actually works... [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop [LWN.net] If this actually works... [LWN.net] Enthralling and enlightening!! [LWN.net] How does this combine with CISA deadlines for patching? [LWN.net] There's AI slop and anti-AI slop [LWN.net] There's AI slop and anti-AI slop Gentoo is for my stupid show off !! [LWN.net] Our editor-in-chief's inimitable dry humor [LWN.net] Stability [LWN.net] If this actually works... [LWN.net] Childish or not childish, that is the question [LWN.net] Childish or not childish, that is the question [LWN.net] tier support exist already in a fashion [LWN.net] There's AI slop and anti-AI slop [LWN.net] Would source code signing be an alternative? [LWN.net] Would source code signing be an alternative? [LWN.net] Power trip? [LWN.net] There's AI slop and anti-AI slop [LWN.net] Haha, AI can't do $THING [LWN.net] Hot patching? [LWN.net] Escalating from root to kernel [LWN.net] Hot patching? [LWN.net] Only global root can mount Good, bad and probabilistic [LWN.net] Hot patching? [LWN.net] Childish or not childish, that is the question [LWN.net] Escalating from root to kernel [LWN.net] tier support exist already in a fashion [LWN.net] Childish or not childish, that is the question Would source code signing be an alternative? [LWN.net] Would source code signing be an alternative? [LWN.net] jqwik 1.10.0 pulled, 1.10.1 replaces it with modified prompt [LWN.net] Magical incantations [LWN.net] Copyright license? I thought the LLM community didn't believe in those... [LWN.net] Copyright license? I thought the LLM community didn't believe in those... [LWN.net] Preparations for the Future [LWN.net] Nonsense [LWN.net] Stability [LWN.net] Copyright license? I thought the LLM community didn't believe in those... [LWN.net] Copyright license? I thought the LLM community didn't believe in those... [LWN.net] Copyright license? I thought the LLM community didn't believe in those... [LWN.net] Copyright license? I thought the LLM community didn't believe in those... [LWN.net] Security issues [LWN.net] Like tears in rain [LWN.net] FUSE-required should be the goal [LWN.net] FUSE-required should be the goal [LWN.net] Just 12 vulnerabilities? [LWN.net] FUSE-required should be the goal [LWN.net]
Escalating from root to kernel [LWN.net]
mb · 2026-05-31 · via LWN.net comments

I'm not sure what your point it.
By the same reasoning you could say: See, root will never be locked down, because you can run without lockdown.
That's obviously true.

The important part is:
It must be made **possible** to configure the system in such a way that root does not automatically have kernel privileges.
We are actually not that far away from that goal. The module loading problem can be solved with signing or by disabling module loading or maybe some other methods today.

What cannot easily be solved by an administrator today is that some filesystems are still not safe against malicious images. There are multiple possible ways to get to a solution for this, like mandatory FUSE implementations or implementations in safe languages. But it requires people to acknowledge the problem first. Which I'm not so sure whether it is done today.

Activities for making Linux safe against malicious root or even malicious hardware (to some degree) are ongoing and I very much welcome that. I currently see that AI tools help with that. Patches are currently being merged to fix security vulnerabilities in old drivers that nobody would spend much of their human time on. Which is a good thing in general. Maybe we can see something like this for filesystems, too?