Hacker News new | ask | show | jobs
by LinuxBender 1245 days ago
What impact will this have on anti-tampering software that looks for changes in executable checksums? Tripwire and OSSEC come to mind and both can report their findings to a centralized server. Do package manager integrity tests still work? I assume anyone here using BSD in a PCI environment have already figured something out. Some people also feed checksums into Splunk.
1 comments

Very good point. As per Job snijder's own words [0], "the sshd binary becomes unique on every openbsd machine". So checksum-checking systems will indeed trip everytime.

[0]: https://marc.info/?l=openbsd-tech&m=167388832715992&w=2