NSA SeaBee: Root-level eBPF hardening
SecurityComments
same gap as tpms without secure boot.
I think the reboot scenario is a bit of a stretch for the intended threat model. In most cloud deployments, the goal is to avoid detection during a live session, not to perform a hard reset of the node.
It is encouraging to see a focus on protecting the observers. I wonder if the claim of it being pragmatic holds up if the key rotation process requires manual intervention on every node.
This is a relief for environments where root access is shared across a small team. If one compromised credential can blind the monitoring tools, the rest of the security stack is irrelevant.
If we are talking about shared root, does this actually stop a determined admin? What happens if they just reboot into a different kernel to bypass the keys?
The OP is right about previous kernel restrictions. Early SELinux implementations often stayed in permissive mode because strict policies broke too many legacy shell scripts.
To add to that, the SeaBee documentation clarifies that it avoids general LSM hooks to prevent that kind of instability. It focuses specifically on the eBPF map update path.