Re: RIP hardened-sources
Daniel Cegiełka <[email protected]> Sat, 29 Apr 2017 17:56:10 +0200
| Newsgroups | gmane.linux.gentoo.hardened |
|---|---|
| Message-ID | <CAPLrYETZWnKoxpaA41BfXMOePZmX_T9ne0yjMpAFgBY=PH5LtA@mail.gmail.com> |
2017-04-29 14:47 GMT+02:00 Alex Efros <[email protected]>: > Hi! > > On Sat, Apr 29, 2017 at 01:49:20PM +0200, Luis Ressel wrote: >> I suppose we all just grudgingly switch over to gentoo-sources? > > I wonder for how long time current kernel with grsec will be more safe and > protected against new exploits than up-to-date gentoo-sources… > Something new in security: avoid updates to have better protection. It's not about grsecurity, it's about PaX. This was the basic layer of protection. Gentoo Hardened has spent years working to provide PaX support in userland. It was the core of this project. Alpine Linux and others are also based on PaX. After years of building _trust_, it all disappears overnight. You can use Grsecurity, you can use SELinux, you can use RSBAC, but you do not have a good alternative for PaX. And this is an existential problem for all these projects. By the way, I don't know what the Gentoo Hardened or Alpine Linux have done wrong, that now are left out in the cold. Instead of complaining, we have to decide what to do next. In my opinion, it is critical to maintain support for PaX* for future kernels. It will not be easy, so I'm right away saying that Gentoo Hardened, Alpine Linux etc. should join forces in realizing this project. I think there will be more people who will be interested in... * https://www.grsecurity.net/~paxguy1/ Daniel