Re: SLFS as an extention to LFS
Robert Day <[email protected]> Wed, 24 Dec 2003 08:15:59 -0500
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
Hmmm.. definately another link or two in my SLFS bookmark folder.... If nothing else, the research done there can be used. I guess it should be noted that SLFS will not be the end-all-be-all of security, no matter how it is built. There will always be some way to get in... But, if you close 99% of the holes, the other 1% are either too hard to exploit, or too hard to patch. If you are using a 2.2 kernel, you are limited on what software you can install on it, as 2.4 kernels add new features, including some security ones, that do not exists in 2.2 etc. so where is the balance? LOL I think we will (they will?) end up using 2.4 for the base kernel, at least till 2.6 gets well tested and probably reaches 2.6.10 or so. 2.2 is, IMHO, too old, and 2.6 is too new. Hopefully, this project gets off the ground, and time will tell where it goes. Rob Day (BOFH) On Wed, 2003-12-24 at 06:42, Björn Thalheim wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > Robert Day schrieb: > > Anyhow, if it is decided finally that SLFS is to be patched into LFS, > > then I cannot change that, but I also cannot help much. It goes against > > what I believe security to be, and until it is complete, and prooven to > > be secure, and stable as the goals dictate it is to be, I can't trust it > > - I would feel constantly like I am building Fort Knox on top of a > > sandpit, instead of a reinforced concrete foundation with all the latest > > alarm technology. > > Well, there have been people who tried the same. The whole thing is a > microkernel that was verified as far as possible. > > http://os.inf.tu-dresden.de/vfiasco/ > > Indeed, you have the problem that you need to build a system completely > new and examine every part under the security aspect. Entire research > groups have worked on this. vfiasco is not the only example for this, > another one is mikrosina. > > http://os.inf.tu-dresden.de/mikrosina > > You might want to read into that to get some idea of how you can > approach the whole thing. > > I love your idea and a lot of other people do, at least from what I > heard from some students here in the department for computer science > (I'm a stundent myself). > > There's one thing that mikrosina and vfiasco tell us: until the kernel > is not secure and proven, all other security measures are a Fort Knox > build on a sandpit. > So there's a serios point in not using the latest kernel but a version > that has been quite long released ... this one was tested for a longer > time and it's less likely to find another vulnerability. Or you might > even try to use a microkernel, this would be a quite interesting task, > because you can use fiasco and then put an L4 on it but only with a > kernel version 2.2.*. > > Regards, > > Björn Thalheim > > > - -- > * Knghtbrd notes he has mashed potatoes for brains tonight > <Valkyrie> yum, can I have some? > <Knghtbrd> um ... > * Knghtbrd hides from Valkyrie > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.0.6 (GNU/Linux) > Comment: For info see http://www.gnupg.org > > iD8DBQE/6Xuvc9uiQ6kr+VcRAvSkAKCMgwTJlc7WB7GNr99HmrdGRgf5lgCfQOPV > JojhX4SkWBCoUJC7debOrbg= > =cSN0 > -----END PGP SIGNATURE----- > -- http://linuxfromscratch.org/mailman/listinfo/lfs-security FAQ: http://www.linuxfromscratch.org/faq/ Unsubscribe: See the above information page