Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You have my vote. Static kernels are the way to go for production systems. This also gets rid of some nasty dance-steps in case your boot device needs a driver that loads as a module. Ram disks to get around such limitations are pretty easily subverted and hardly anybody ever looks at what is actually going on in there which makes them an excellent place to pull tricks.


For firewalls, the solution is simple: Choose your hardware carefully.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: