> The only truly secure way to record messages up to the point of break-in is a one-way remote log.
And if you have this then you don't need a fancy cryptographic syslogd to detect tampering.
And if you have this then you don't need a fancy cryptographic syslogd to detect tampering.
Security half-measures do not mean you are secure. If it can be hacked, it will be hacked, and then what was the point of sacrificing your whole system's init system?
(Also you could just replace syslogd with a journaled syslogd, rather than replacing your entire init system... but I guess that's off-topic?)