logoalt Hacker News

chromacityyesterday at 10:19 PM3 repliesview on HN

This is a pedantry for the sake of it. If it's present by default and an attacker can trivially cause it to be loaded, it's the same as "on by default".


Replies

akerl_yesterday at 10:28 PM

It’s radically different than on by default.

Having a service that automatically starts and listens on the network is radically different from having a module that a local administrator can load.

If you want to block module loads, you’re one sysctl flag away.

show 3 replies
Sohcahtoa82yesterday at 10:50 PM

> This is a pedantry for the sake of it.

Par for the course for HN.

thaynetoday at 2:01 AM

How would the attacker cause one of these modules to get loaded without already having root?

show 2 replies