>So one solution would be to get the
>fingers-of-one-hand applications still
>using the interface off it onto user-mode
>software-only and then make it
>kernel-only, closing the door on the entire
>attack surface from user space

Perhaps the mantra, “never break user space” needs rewriting as, “break user 
space only when something is already broken” (such as when the number of CVEs 
already associated with that thing exceeds some smallish positive integer N, 
say, 5).

Duck

Reply via email to