Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

eBPF is restricted when booted in a SB environment, but it's not nonfunctional. The default config puts the kernel into "integrity" mode of Kernel Lockdown, which reduces scope of access and enforces read-only usage.

Whether or not the specific functions needed to replicate this tool are impacted is beyond my knowledge.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: