<?xml version="1.0"?>
<rss version="2.0">
  <channel>
    <title><![CDATA[Report external file editing]]></title>
    <link>http://brainstorm.ubuntu.com/item/6416/</link>
    <description><![CDATA[Report, via a non intrusive popup (libnotify style or something) when<br />a)Files have been edited when the system was shutdown. <br />b)Files in a users home directory have been edited more recently then the last time they logout <br /><br />a simple message like <br />"files have been modified since the system was last successful shutdown/logout, click to see details"<br />would cover the fact that it will be triggered in the event of a crash. clicking for details could then trigger a more detailed analysis.<br /><br />There are obviously security flaws with this, an attacker can spoof the file edit times, an attacker would be able to disable the reporting system, etc, but some security would be gained against simple attacks (like logging in at recovery mode, or using a live CD)<br />
<br />


<b>[-7 votes] Solution #1: Auto-generated solution of idea #6416</b>
<br />

<br />
<br />



]]></description>

    <language>en-us</language>
    <pubDate>Sat, 05 Apr 2008 03:01:22 +0000</pubDate>
    <lastBuildDate>Mon, 19 May 2008 22:22:25 +0000</lastBuildDate>
    <generator>QAPoll module</generator>
    <guid isPermaLink="true">http://brainstorm.ubuntu.com/idea/6416/</guid>
        <item>
  <title>Comment from Rioting_Pacifist</title>
  <description><![CDATA[why is it being voted down. for those that dont want it it could be disabled, but for the rest it will improve security]]></description>
  <pubDate>Sat, 05 Apr 2008 14:48:15 +0000</pubDate>
</item>
        <item>
  <title>Comment from 3wings</title>
  <description><![CDATA[Which files should be checked?<br /><br />In any case, this adds unnecessary overhead (hashing files at logon, comparing to hash database, updating hash database at logoff).]]></description>
  <pubDate>Wed, 23 Apr 2008 22:08:56 +0000</pubDate>
</item>
        <item>
  <title>Comment from bochecha</title>
  <description><![CDATA[-1 for two reasons:<br /><br />* "Files have been edited when the system was shutdown."<br />Duh! How can a file be edited if the system is shut down? -_-'<br /><br />* as sayd by 3wings, this would cause *a hell of a lot* of overhead.<br /><br />If you want to be sure important files have not been edited during your absence, just save a hash of those files, then check them back.<br /><br />Once you saw how much time it takes for some files, you'll understand why it can absolutely *not* be done at log in/out.]]></description>
  <pubDate>Mon, 19 May 2008 22:22:25 +0000</pubDate>
</item>
      </channel>
</rss>

