This is the Washington Post interview he wrote this for: http://www.washingtonpost.com/sf/business/2015/11/05/net-of-... Source: https://twitter.com/grsecurity/status/662393322699415554 > Very fair article on the topic of Linux security: [...] … Was a pleasure talking with @craigtimberg
The comments in the HN submission must be some new record in middlebrow dismissals. https://news.ycombinator.com/item?id=10515817
Grsecurity Developer Spender's Feelings on the State of Linux Security
11–20 of 80 posts
Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#12Couldn't agree more. I feel that we, as entire IT industry, have failed to provide robustness, security, and privacy after dozens of years of development of Internet technologies. Just take the recent vulnerabilities in Android and iPhones, used everyday by millions of people worldwide. How could that happen after so many billions of dollars invested in the development of the major technology used nowadays? We failed miserably and don't even understand the root problems.
Of course, completely different thing is functionality: here we've seen tremendous improvements over the years - which is very positive - but that's another story.
Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#13The Gentoo Hardened Project makes using grsec/PaX relatively easy. https://wiki.gentoo.org/wiki/Project:Hardened
Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#14> The industry is entirely broken in terms of what it values. Couldn't agree more. I feel that we, as entire IT industry, have failed to provide robustness, security, and privacy after dozens of years of development of Internet technologies. Just take the recent vulnerabilities in Android and iPhones, used everyday by millions of people worldwide. How could that happen after so many billions of dollars invested in th…
Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#15The Gentoo Hardened Project makes using grsec/PaX relatively easy. https://wiki.gentoo.org/wiki/Project:Hardened
I used to be a security freak guy. Using the Gentoo Hardened, GRSecurity PaX/RBAC, customized ACLs, etc. IMHO is a high-quality piece of software, very polished and well-designed... I'm a Ubuntu guy today. For my small business, such level of security is too much time consuming, drawing me back. It's kinda sad.
I used to make my own Linux distribution, from scratch, with Grsecurity, PaX/RBAC for everything.
Then it wasnt so usable, when I needed new packages/software, or upgrades, compiling was tiresome, and I didnt know how to make a package manager, or how to automate everything.
I assumed somebody else would do it, a big multi billion dollar company perhaps, since I was just 16 year-old doing that over a summer, they would do better, right?
Oh how sad. Nobody really cares about security.
Since, enterprises just use lawyers instead of security.
Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#16Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#17I used to look up to Linus Torvalds as many did, but am increasingly beginning to see him as a threat to the advancement of the industry with his faux pragmatism that has led him to speak out against everything from security to microkernels and kernel debuggers.
[1] https://www.doc.ic.ac.uk/~cristic/papers/fo-osdi-04.pdf
[2] http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.52....
[3] https://www.usenix.org/legacy/events/sec02/full_papers/kiria...
[4] https://www.cs.columbia.edu/~angelos/Papers/2007/mmm-acns-se...
Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#18Aye, too many people have this defeatist attitude that since perfect security will never be possible, therefore the only valid solution is reactive security (bug-patch cycles). Patch dependence is considered too entrenched for making some changes like replacing ambient authority with capabilities, using failure-oblivious computing [1] to redirect invalid reads and writes, using separation kernels, information flow co…
At the time he was against microkernels it would be fair to say monolithic kernels did definitely have (and continue to have) performance advantages over microkernel architectures. Have things changed? Somewhat. Some of how OS kernels are used has changed and that has made microkernels more attractive again.
I feel the rest of your argument just feels like the jab at Linus is tacked on though because he doesn't seem to be against capabilties system. (infact the kernel has what? 3 capabilities systems?) Nor does he seem against forms of multi-level security or program shepherding. So maybe those weren't meant to be directed at him.
Either way I just wanted to say that people should give him some slack, his job isn't to please security zealots but to ship software all of us use and many of us depend on for our livelihood in a timely and reliable manner.
Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#19Everyone uses their software, firewalls, servers, email serves, openssl is everywhere, corporate/bank cluster without BSD or Linux with grsecurity is unimaginable.
I recently started donating to opensource project I use everyday. I realised how little they ask for, F-Droid, I easily doubled their BTC found used to cover server maintenance, LibreOffice asks for 3EURO donation by default (also BTC)! OpenBSDFundation asks for 10$ per month.
https://grsecurity.net/contribute.php
Edit: I also found a nice way how to donate to Tor, there is a site https://oniontip.com/ where you can donate others for running Tor nodes, one of two top 200nodes has WikiLeaks BTC address, another one goes to my wallet and I send it back to TorProject. I had enough free resources, I used them :)
Re: Grsecurity Developer Spender's Feelings on the State of Linux Security
#20That looks like a political problem. Maybe the state should fund security for its citizens - maybe we need some new kind of institutions to do this.