• ozymandias117@lemmy.world
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    If the executable binary has to be signed with a key, similar to the module signing key, Microsoft could sign their binaries

    This, along with secureboot, would prevent the owner of the machine from running eBPF programs Microsoft doesn’t want you to run, even with root