| ▲ | jerf an hour ago | ||||||||||||||||
Nobody is claiming this is a complete solution to security. I would call this "necessary but not sufficient". You won't get far as an engineer if you refuse to implement "necessary but not sufficient" changes because the change doesn't in and of itself one-shot the entire problem. | |||||||||||||||||
| ▲ | rcxdude 35 minutes ago | parent [-] | ||||||||||||||||
The fact that it's not sufficient also largely means it's not necessary either, because the real solution is auditing and trusting the codebase as a whole. All you do when disabling install hooks is make a lot of situations much more difficult to handle. | |||||||||||||||||
| |||||||||||||||||