systemd-journald provides tampering-attestation features that plain-text logs do not, and cannot, provide. It's fundamentally more secure.
systemd-journald provides tampering-attestation features that plain-text logs do not, and cannot, provide. It's fundamentally more secure.
Reality: if I owned the user writing logs, I can do anything I want with the logs, no matter how they're stored.
Here is something you cannot do: you cannot alter the logs without anyone noticing, since log entries have a rolling hash.
This prevents an attacker from being able to modify logs without detection, and was implemented in systemd after the postmortem on the kernel.org breakin, i.e., it was developed to counter an actual threat.
I would suggest you read up on what log attestation actually does.
The only truly secure way to record messages up to the point of break-in is a one-way remote log. Any new messages after break-in is subject to falsification.
And if you have this then you don't need a fancy cryptographic syslogd to detect tampering.
Security half-measures do not mean you are secure. If it can be hacked, it will be hacked, and then what was the point of sacrificing your whole system's init system?
(Also you could just replace syslogd with a journaled syslogd, rather than replacing your entire init system... but I guess that's off-topic?)
FAIL. You just wrote outdated software. Under this dumbass idea of journaling, which by defition is there to allow editing.., the best thing you can do is built a rolling function, which basically means coping the data, which basically means increasing your attack surface.
Assuming nothing has managed to redirect those unlinks for example...
As soon as the attacker manages to extract the state of the key generator from memory at one point of time, the log entries from that and the following sealing periods can be modified and cleanly sealed.
These remote copies of the logs could actually be used to detect log-tampering and 0day exploits.
anything can have any feature, what matters is how it's built.