On Fri, 2008-05-09 at 09:24 -0400, Noah Meyerhans wrote:
>
> At least tripwire has the ability to encrypt its database, which helps
> to mitigate this problem. The claim that tripwire is only useful with
> read-only media is too strong; it can be quite useful without it.
>
And you can sign your datebase with aide. (Tripwire's encryption
approach costs more resources.)