Re: Security features in Debian 8 (Jessie)

Javier Fernández-Sanguino Peña <[email protected]>
Newsgroups gmane.linux.debian.devel.www
Message-ID <[email protected]>
On Mon, Apr 27, 2015 at 07:32:18PM +0200, [email protected] wrote:
> 	You wrote that these hardening flags are individual for all packages.
> So is it possible to see which packages have which build flags
> enabled? (via the new package tracker or the package search). 

In https://wiki.debian.org/ReleaseGoals/SecurityHardeningBuildFlags you will
find pointers to the list of packages have these features enabled. These are
maintained by the team driving the process and they list those that are
fixed, partially fixed and being workd on or checked:

Packages of priority important or higher:
http://anonscm.debian.org/viewvc/secure-testing/hardening/subgoal-important.txt?view=co

Network-accesible daemons:
http://anonscm.debian.org/viewvc/secure-testing/hardening/subgoal-daemons.txt?view=co

Interpreters:
http://anonscm.debian.org/viewvc/secure-testing/hardening/subgoal-interpreters.txt?view=co

Packages with a DSA since 2006:
http://anonscm.debian.org/viewvc/secure-testing/hardening/subgoal-dsa.txt?view=co

You also have some statistics here:
http://outflux.net/debian/hardening/

> 	It's not practicable to install each package and test it with a
> script or look in the build file. 

No need to do that, the script used for the statistics uses a local mirror to
obtain the information. 

> 	And for the kernel hardening: -fstack-protector and runtime memory
> allocation validation  are not exactly described in the
> https://wiki.debian.org/Hardening [1] page. 

The Wiki just has references to these features. The description of those
exact security features should be found elsewhere (in the Linux kernel
documentation)

> 	I'd like to express with the wiki page (the Security Features Matrix)
> that it would be nice to see all information at one point. Probably it
> would be good to include such a Matrix in the official documentation
> or the release notes. I know that the Debian project is working
> heavily on security, but the documentation of this process is not very
> good. 

Yes, the documentation can be improved but, unfortunately, just "wishing" it
to be done is not going to get it done. We are, after all, a volunteer
organisation. People are working on a lot of things and some others can get,
from time to time, neglected.

Unfortunately, documentation is sometimes neglected. But I encourage you to
help in the documentation, if you so desire, the process is open to anybody
with a willingness to improve it.

Best regards

Javier
signature.asc (application/pgp-signature, 811 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIVAwUBVUK/PDg8os7RvajdAQiXNA/7B9fQB4dsieMxwltVQKoKO7RfpiAK3M7X
clkFR0pNfv8y70Hn9jrf+aOAIgrslyP43CJIaPLvtJJYEJfp3AC3I7CSQAcCFj8x
72D1w1sO7X5jJb2Z8lOO5Tahf70uEsFn3UYooh7ISb3hyIpAIgLWQ+5BbsGB/nkS
Boqo5PPB7wg/k9VMrhMrkNXm+Yag+wUN4QbVTE7tEgWm85VyaxK3X5RTNyma8e0+
IkWORA+XCTupe2fOz1Qa4+3Plnhgz4MXwDpAc+CO/YDnMeqI1LeYj7kMmIU3MWCB
3m3JJQ1gdPdP9XXGuk02XktaaryV0N0UEkPVfeyB4jPPESJPFu2UEFK0aPk3h4zJ
xbXi34de6kRoUR6TnXhxldas6LWndj/e1FdpsxVOIozaiVAUuIK9M48dprPkmPAO
/SXjT0ykyJgTg+wv3RLk3vSfOKbz3DozSuk1jSfkxui4BNIueyKnvUoHtZMu65s5
XcSr5NqFgOfJ41LOI74geIhASwpfPnRfAnt17+TUx/oji2rQYa/DOZ35I8dGILtL
oCTvTNaan1kUBfz0o0yjBKx2XDgL7cWLBjR8FBD8QHRCkXYxKclvGzK4ajsz5xue
iLSV2ucYl9Rfe4AZFec1YwAhLBQlAXlJ4UuGmuSphJx9mTUAZGW10d+JcUDkmB1h
Odv3FyxnIBo=
=O4Gd
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.