Hacker News new | ask | show | jobs
by a-dub 909 days ago
that's part of it. and is the basis of the classic tannenbaum v. torvalds debate, but only part of what i mean.

it would be interesting if there were some kind of write protection on the process-privilege data where some effort is made to verify the provenance of updates before they're allowed to go through or maybe even the whole privilege table is centralized and signed.