|
|
|
|
|
by cube00
28 days ago
|
|
> any kind of secure boot / boot chain attestation [...] rebooting clears out pretty much all malware IMHO "pretty much" understates the risk. Malware can easily install itself as a system service, timer unit, XDG autostart or your shell profile among other places. I'll be the first to admit I never check all these places regularly. The only thing that should be putting minds at ease is regular OS installs from fresh images. Resist the temptation to do an "in place" upgrade and go with a clean ISO each time your distro comes out with a new major version. It's a pain but thanks to configuration management or even shell scripts it's manageable for me now. Admittedly six months is probably too long as well but at least it stops something lurking on a server or my desktop for years. |
|