Hacker News new | ask | show | jobs
by michaelt 696 days ago
> Crowdstrike already runs in user-mode on both Mac and Linux (from what I can tell),

Crowdstrike provides a Linux kernel module, and expects users to manually install an extra Secure Boot key for it, as part of their corporate laptop setup procedure.

This has always seemed inadvisable to me, but checkbox checkers gotta check checkboxes I guess.

1 comments

They also support (and recommend I think?) an eBPF-based sensor