Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I mean, to me that's just a convincing argument against using kernel-mode spywa-, err, endpoint protection, with OTA updates that give you no way to stage or test them yourself cannot be secure.


How are those arguments against kernel level detection from a security perspective? His arguments show that without kernel level, you either can't catch all bad actors as they can evade detection, or that the latency is too big that an attacker basically has free reign for some time after detection.


Easy: plenty people in this forum aren't entrenched in the security field.

That's why there are so many misinformed assumptions




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: