Tetragon security model ?
Tetragon security model ?
Posted Jul 13, 2026 15:51 UTC (Mon) by Lionel_Debroux (subscriber, #30014)Parent article: Shielding running kernels against exploits with BPF
Tetragon immediately made me think about https://grsecurity.net/tetragone_a_lesson_in_security_fun... .
It's been 4 years since that post which described why Tetragon's security model couldn't work, which brings the question: did things change since then, considering that from what I can gather, the usage of same privilege level technologies (BPF, kprobes, uprobes, LSM hooks) remains ?
It's been 4 years since that post which described why Tetragon's security model couldn't work, which brings the question: did things change since then, considering that from what I can gather, the usage of same privilege level technologies (BPF, kprobes, uprobes, LSM hooks) remains ?