























Huh?
I got a headache trying to parse your point (and I still don't see one).
> As a result, any security design that depends on "root processes cannot get kernel privileges" on Linux needs you to be aware of the exception "unless there is owner consent", as opposed to the iOS variant, where the exception is "unless Apple as kernel developer consents".
You are describing a distinction without a difference. With Apple, the entity with the keys (Apple) is the owner and escalation may happen with its consent. With Linux, the entity with the keys is the owner (maybe local admin, maybe not) and escalation may happen with its consent. Your point?
Note: you can avoid this step in the future by logging into your LWN account.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。