(no title)
ballard | 12 years ago
In a positive direction, it would be nice to be able to be able to strip out more functionality and still produce a functional kernel. Unfortunately, I don't think this is scalable with autotools or any configuration management setups without having more #ifdefs than code. Haskell could be a good candidate for such a kernel framework, but I'm sure there are other functional and imperative languages that have better complex configuration mgmt support with formal verification.
hga|12 years ago
The attack surface will still be huge, but perhaps by such hiding you can make it too hard for an attacker to actually get to it.