Matthew Garrett ([personal profile] mjg59) wrote 2011-09-23 05:27 pm (UTC)

At some level, any anti-malware code has to trust the services provided to it by the operating system. If the operating system has already been compromised before the anti-malware code can be executed, you've lost. The attack this is intended to prevent is the one where a compromised system modifies early parts of the boot process such as the bootloader and uses that to backdoor the entire OS. If each component you execute before loading the anti-malware code is signed, you have a much stronger expectation that the OS will behave reliably when asked about things like "Does this file exist".

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org