Re: Secure Linux From Scratch

ashes <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Utopia Inc
Message-ID <[email protected]>
On December 19, 2003 08:17 am, Robert Day wrote:
...
> Simple answer, if Pax requires that much, then we don;t use it. Not till
> the required subsystems are available as part of LFS. We're not
> replacing LFS here with a cutting edge system.  One of the key points in
> security is using tested, stable packages. You can't build a secure box
> using insecure packages as a foundation. If the gcc 3.4, being so new,
> has a flaw, that flaw propagates to every package in the system. Imagine
> the errata we'd have to release if a bug was found in gcc that allowed a
> buffer overflow to occur in any package compiled with that compiler that
> used XXXX system call?

Not all of gcc-3.4 needs to be imported, just the -pie patch. By the time the 
book is stable, it may not be so cutting edge. We still do not have SLFS 
project goals defined, but certainly they would all have to be met before the 
release, and tested to the best of our ability. Gcc-3.3 is still an option, 
its just not as powerfull as gcc-3.4's. Personaly I have no interest in 
testing the gcc-3.3 method because I know it will become obsolete in the not 
to distant future. If anyone else wants to get gcc-3.3's et_dyn working feel 
free. There's no reason to jump the gun on this and pop out a release asap. 
If we do, it would make the project less creditable, and secure. It should be 
unique. I feel it should be something like a good crash course in hacking, 
and of course how to prevent it on you. Instead of just saying its secure, 
show real life examples why. I think that implies we have to try to break 
every aspect of the system, and don't issue a release untill is passes any 
torture we can cook up.


-- 
http://linuxfromscratch.org/mailman/listinfo/lfs-security
FAQ: http://www.linuxfromscratch.org/faq/
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.