Live data from Hacker News

Grsecurity Developer Spender's Feelings on the State of Linux Security

grsecurity.net

11–20 of 80 posts

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#11
post #6
post #3

This is the Washington Post interview he wrote this for: http://www.washingtonpost.com/sf/business/2015/11/05/net-of-... Source: https://twitter.com/grsecurity/status/662393322699415554 > Very fair article on the topic of Linux security: [...] … Was a pleasure talking with @craigtimberg

The comments in the HN submission must be some new record in middlebrow dismissals. https://news.ycombinator.com/item?id=10515817

Astonishingly so, since it's actually a very good article. Only one or two (minor) flaws in a long article about a technical subject, written by a journalist, is a good tally.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#12
> The industry is entirely broken in terms of what it values.

Couldn't agree more. I feel that we, as entire IT industry, have failed to provide robustness, security, and privacy after dozens of years of development of Internet technologies. Just take the recent vulnerabilities in Android and iPhones, used everyday by millions of people worldwide. How could that happen after so many billions of dollars invested in the development of the major technology used nowadays? We failed miserably and don't even understand the root problems.

Of course, completely different thing is functionality: here we've seen tremendous improvements over the years - which is very positive - but that's another story.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#13
post #5

The Gentoo Hardened Project makes using grsec/PaX relatively easy. https://wiki.gentoo.org/wiki/Project:Hardened

I used to be a security freak guy. Using the Gentoo Hardened, GRSecurity PaX/RBAC, customized ACLs, etc. IMHO is a high-quality piece of software, very polished and well-designed... I'm a Ubuntu guy today. For my small business, such level of security is too much time consuming, drawing me back. It's kinda sad.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#14
post #12

> The industry is entirely broken in terms of what it values. Couldn't agree more. I feel that we, as entire IT industry, have failed to provide robustness, security, and privacy after dozens of years of development of Internet technologies. Just take the recent vulnerabilities in Android and iPhones, used everyday by millions of people worldwide. How could that happen after so many billions of dollars invested in th…

I think Google has understood the systemic security problems in Android pretty well since the beginning, but adopted a typical data driven approach: gather data, and when/if phones start getting compromised start figuring out what countermeasures are cost effective.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#15
post #5

The Gentoo Hardened Project makes using grsec/PaX relatively easy. https://wiki.gentoo.org/wiki/Project:Hardened

I used to be a security freak guy. Using the Gentoo Hardened, GRSecurity PaX/RBAC, customized ACLs, etc. IMHO is a high-quality piece of software, very polished and well-designed... I'm a Ubuntu guy today. For my small business, such level of security is too much time consuming, drawing me back. It's kinda sad.

Same here.

I used to make my own Linux distribution, from scratch, with Grsecurity, PaX/RBAC for everything.

Then it wasnt so usable, when I needed new packages/software, or upgrades, compiling was tiresome, and I didnt know how to make a package manager, or how to automate everything.

I assumed somebody else would do it, a big multi billion dollar company perhaps, since I was just 16 year-old doing that over a summer, they would do better, right?

Oh how sad. Nobody really cares about security.

Since, enterprises just use lawyers instead of security.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#16
I would think that everyone here agrees that 'computer' security is in a state of turmoil. Is it possible to design a computing system that fails-safe in the event of a bug in a component, instead of opening the entire system up to exploits. Fails Safe as in the process does nothing or restricts the targeted surface area of the malware.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#17
Aye, too many people have this defeatist attitude that since perfect security will never be possible, therefore the only valid solution is reactive security (bug-patch cycles). Patch dependence is considered too entrenched for making some changes like replacing ambient authority with capabilities, using failure-oblivious computing [1] to redirect invalid reads and writes, using separation kernels, information flow control, proper MLS [2], program shepherding for origin and control flow monitoring [3] and general fault tolerance/self-healing [4].

I used to look up to Linus Torvalds as many did, but am increasingly beginning to see him as a threat to the advancement of the industry with his faux pragmatism that has led him to speak out against everything from security to microkernels and kernel debuggers.

[1] https://www.doc.ic.ac.uk/~cristic/papers/fo-osdi-04.pdf

[2] http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.52....

[3] https://www.usenix.org/legacy/events/sec02/full_papers/kiria...

[4] https://www.cs.columbia.edu/~angelos/Papers/2007/mmm-acns-se...

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#18

Aye, too many people have this defeatist attitude that since perfect security will never be possible, therefore the only valid solution is reactive security (bug-patch cycles). Patch dependence is considered too entrenched for making some changes like replacing ambient authority with capabilities, using failure-oblivious computing [1] to redirect invalid reads and writes, using separation kernels, information flow co…

I wouldn't be so harsh. Linus thinks and works in the here and now. He is neither interested in the theoretical or bothered by what theoretical people have to say about him. He ships code that works and works well and generally speaking has a good security track record compared to many userspace systems (Adobe Flash anyone?).

At the time he was against microkernels it would be fair to say monolithic kernels did definitely have (and continue to have) performance advantages over microkernel architectures. Have things changed? Somewhat. Some of how OS kernels are used has changed and that has made microkernels more attractive again.

I feel the rest of your argument just feels like the jab at Linus is tacked on though because he doesn't seem to be against capabilties system. (infact the kernel has what? 3 capabilities systems?) Nor does he seem against forms of multi-level security or program shepherding. So maybe those weren't meant to be directed at him.

Either way I just wanted to say that people should give him some slack, his job isn't to please security zealots but to ship software all of us use and many of us depend on for our livelihood in a timely and reliable manner.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#19
It always make me sad when I hear BSDs are underfunded, OpenBSD was about to "turn off the lights", FreeBSD was in sersious problems before they got 1M$ donation from WhatsApp. Heartbleed bug in OpenSSL? They also didn't have enough (full time) developers to even review the code. Now grsecurity makes me feel bad about it.

Everyone uses their software, firewalls, servers, email serves, openssl is everywhere, corporate/bank cluster without BSD or Linux with grsecurity is unimaginable.

I recently started donating to opensource project I use everyday. I realised how little they ask for, F-Droid, I easily doubled their BTC found used to cover server maintenance, LibreOffice asks for 3EURO donation by default (also BTC)! OpenBSDFundation asks for 10$ per month.

https://grsecurity.net/contribute.php

Edit: I also found a nice way how to donate to Tor, there is a site https://oniontip.com/ where you can donate others for running Tor nodes, one of two top 200nodes has WikiLeaks BTC address, another one goes to my wallet and I send it back to TorProject. I had enough free resources, I used them :)

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#20
post #8

That looks like a political problem. Maybe the state should fund security for its citizens - maybe we need some new kind of institutions to do this.

Currently states is looking for a way to legally hack into your phone, computer, tablets, intercept all kind of communication and read offline data without warrant. It's not how that works nowadays.
Post reply on HN