Re: Secure Linux From Scratch
ashes <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Organization | Utopia Inc |
| Message-ID | <[email protected]> |
On December 19, 2003 08:17 am, Robert Day wrote: ... > Simple answer, if Pax requires that much, then we don;t use it. Not till > the required subsystems are available as part of LFS. We're not > replacing LFS here with a cutting edge system. One of the key points in > security is using tested, stable packages. You can't build a secure box > using insecure packages as a foundation. If the gcc 3.4, being so new, > has a flaw, that flaw propagates to every package in the system. Imagine > the errata we'd have to release if a bug was found in gcc that allowed a > buffer overflow to occur in any package compiled with that compiler that > used XXXX system call? Not all of gcc-3.4 needs to be imported, just the -pie patch. By the time the book is stable, it may not be so cutting edge. We still do not have SLFS project goals defined, but certainly they would all have to be met before the release, and tested to the best of our ability. Gcc-3.3 is still an option, its just not as powerfull as gcc-3.4's. Personaly I have no interest in testing the gcc-3.3 method because I know it will become obsolete in the not to distant future. If anyone else wants to get gcc-3.3's et_dyn working feel free. There's no reason to jump the gun on this and pop out a release asap. If we do, it would make the project less creditable, and secure. It should be unique. I feel it should be something like a good crash course in hacking, and of course how to prevent it on you. Instead of just saying its secure, show real life examples why. I think that implies we have to try to break every aspect of the system, and don't issue a release untill is passes any torture we can cook up. -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page