Lennart Poettering, never a stranger to controversial projects, and Kay Sievers have proposed to create a new, git inspired, logging system for Linux. The new system would be a cryptographically verifiable binary format that would stand in sharp contrast to the usual UNIX way of doing things with simple text files that can be easily accessed by all manner of tools.
Break-ins on high-profile web sites have become very common, including the recent widely reported kernel.org break-in. After a successful break-in the attacker usually attempts to hide his traces by editing the log files. Such manipulations are hard to detect with classic syslog: since the files are plain text files no cryptographic authentication is done, and changes are not tracked. Inspired by git, in the journal all entries are cryptographically hashed along with the hash of the previous entry in the file. This results in a chain of entries, where each entry authenticates all previous ones. If the top-most hash is regularly saved to a secure write-only location, the full chain is authenticated by it. Manipulations by the attacker can hence easily be detected.
The plan is to get an initial implementation into the Fedora 17 release.
Comment on this story via Google+.
Recently Popular
- Canonical's Board Decimated As 2 More Employees Leave
- Gnome Shell Notifications Explained
- The Solarized Palette
- Gnome 3 Wallpapers
- Citrus: New UI Proposal for Libre Office
- Add Some Useful Tweaks to Gnome 3
- Red Hat is "Obfuscating" the RHEL 6 Kernel Source
- The Future of Linux Mint
- Ubuntu is Shutting Down Off-Topic Mailing List
- Apple Threatens Small, Family-Run Café Over Trademark
Tags
amazon announcement apple canonical cracking design development elopcalypse fedora financial firefox gaming germany gnome gnome3 gnomeshell google government gpl hacked java kernel legal licensing markshuttleworth meego microsoft mozilla nokia novell oracle patents phones playstation politics redhat releases samsung security sony tablets ubuntu unitedstates windows windowsphone
Topics
LXNews covers everything to do with the Linux kernel, Android, free and open source software, the web, digital rights and free culture. We also cover proprietary software, companies and international politics where those intersect with the aforementioned issues. We believe that software freedom is worthless without personal freedom both as a citizen and as a consumer.Open Source News
You can see the news come in via our freelish.us feed before they hit the site and if you think we have missed an important story, please submit it via this form.Comments?
To comment on any of the articles posted on the site, please use the provided links under the content and join our identi.ca conversation.









