Live data from Hacker News

Grsecurity Developer Spender's Feelings on the State of Linux Security

grsecurity.net

21–30 of 80 posts

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#21
post #19

It always make me sad when I hear BSDs are underfunded, OpenBSD was about to "turn off the lights", FreeBSD was in sersious problems before they got 1M$ donation from WhatsApp. Heartbleed bug in OpenSSL? They also didn't have enough (full time) developers to even review the code. Now grsecurity makes me feel bad about it. Everyone uses their software, firewalls, servers, email serves, openssl is everywhere, corporate…

Most of us can afford to pay it too. That's the real tragedy.

All of us should consider doing something similar, allocate a couple $ a month and give it to people who make our lives/jobs easier or better.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#22
post #18

Aye, too many people have this defeatist attitude that since perfect security will never be possible, therefore the only valid solution is reactive security (bug-patch cycles). Patch dependence is considered too entrenched for making some changes like replacing ambient authority with capabilities, using failure-oblivious computing [1] to redirect invalid reads and writes, using separation kernels, information flow co…

I wouldn't be so harsh. Linus thinks and works in the here and now. He is neither interested in the theoretical or bothered by what theoretical people have to say about him. He ships code that works and works well and generally speaking has a good security track record compared to many userspace systems (Adobe Flash anyone?). At the time he was against microkernels it would be fair to say monolithic kernels did defin…

At the time he was against microkernels, QNX had already demonstrated they were faster than the monolithic state of the art. [1]

Linux does not have any form of capabilities (maybe Capsicum, but it's not finished). Capabilities are not POSIX capabilities, which redefined a decade-old term, but rather this [2].

The rest is just trite dismissals of the same faux pragmatism that Linus embodies. He's "not interested in the theoretical", as if there is any other? Before the now-mundane ideas became the staples of pragmatists, they were theories hidden in the research literature.

Linus is a major figurehead and his promoting of self-destructive attitudes is undesirable.

In fact, you claim he lives in the here and now. He does not. The here and now has long surpassed him and he now lives in his own realm.

[1] https://cseweb.ucsd.edu/~voelker/cse221/papers/qnx-paper92.p...

[2] http://www.eros-os.org/essays/capintro.html

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#23
post #18

Aye, too many people have this defeatist attitude that since perfect security will never be possible, therefore the only valid solution is reactive security (bug-patch cycles). Patch dependence is considered too entrenched for making some changes like replacing ambient authority with capabilities, using failure-oblivious computing [1] to redirect invalid reads and writes, using separation kernels, information flow co…

I wouldn't be so harsh. Linus thinks and works in the here and now. He is neither interested in the theoretical or bothered by what theoretical people have to say about him. He ships code that works and works well and generally speaking has a good security track record compared to many userspace systems (Adobe Flash anyone?). At the time he was against microkernels it would be fair to say monolithic kernels did defin…

No, nobody should give Linus any slack whatsoever. He's responsible for the current fiasco, where stock Linux kernel is a joke security-wise, one can find reliable vulnerabilities in a few hours, once the debugging infrastructure is there. Compare that with Windows where it's a few weeks to a few months and then a lot more work to get the reliability.

Linus holds the vast majority of the blame here, simply put, he is an idiot when it comes to security or looking ahead at how things will be in a couple of years. Linux is slowly entering every single aspect of our lives and this trend will only accelerate via IoT. Imagine what this means about security with Linus in charge.

We now KNOW that there are intelligent adversaries out there that spend hundreds of millions to defeat security worldwide. It is simply UNACCEPTABLE and downright MALICIOUS STUPIDITY for Linus to hold the views he does in this day and age. He's been repeatedly warned and cautioned for more than a DECADE now and he's laughed at and ignored valid criticisms from people with much more foresight than him. If this trend continues, he should be NAILED to the cross.

A security bug is NOT just a bug.

No, I shouldn't have to DISCONNECT everything that runs Linux from the Internet if I want it to have a modicum of security.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#24
post #5

The Gentoo Hardened Project makes using grsec/PaX relatively easy. https://wiki.gentoo.org/wiki/Project:Hardened

I used to be a security freak guy. Using the Gentoo Hardened, GRSecurity PaX/RBAC, customized ACLs, etc. IMHO is a high-quality piece of software, very polished and well-designed... I'm a Ubuntu guy today. For my small business, such level of security is too much time consuming, drawing me back. It's kinda sad.

You know, that's the problem. There is basically no reason why this is so hard. Many security features could just be enabled by default by major distributions with hardly any downside. You don't even have to look at grsecurity. Just using pie binaries to enable proper ASLR would be a start.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#25
post #9
post #5

The Gentoo Hardened Project makes using grsec/PaX relatively easy. https://wiki.gentoo.org/wiki/Project:Hardened

Anyone that is curious about grsec and comfortable installing a gentoo overlay would have no problem installing grsec on their own; especially if gentoo was not their normal distro. You are not doing anyone any favors by making grsec look like a Sisyphean task without gentoo.

I used to run mandrake many years ago, and there was a -grsec kernel available in their package repository, and it just worked.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#26
post #18

Earlier quoted context omitted.

I wouldn't be so harsh. Linus thinks and works in the here and now. He is neither interested in the theoretical or bothered by what theoretical people have to say about him. He ships code that works and works well and generally speaking has a good security track record compared to many userspace systems (Adobe Flash anyone?). At the time he was against microkernels it would be fair to say monolithic kernels did defin…

At the time he was against microkernels, QNX had already demonstrated they were faster than the monolithic state of the art. [1] Linux does not have any form of capabilities (maybe Capsicum, but it's not finished). Capabilities are not POSIX capabilities, which redefined a decade-old term, but rather this [2]. The rest is just trite dismissals of the same faux pragmatism that Linus embodies. He's "not interested in t…

I didn't really refer to his massive ego in my previous comment, but this is another facet of his idiocy in my opinion. The signs were there 20 years ago, but now one could say that the adorations and worship of vast number of subordinates and minions have all turned him into a monster, like a caricature of the corrupt Roman emperors.

I sure hope some other leading figure emerges and seizes some control over Linux because I sure don't see Linus changing the way he does business.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#27
Grsecurity languishes in (relative) obscurity because no distribution ships it. I know several people who know about it and would pick the option if it was distro-supported. If you don't get automatic updates it's a non-starter.

Popularity in distros would put a lot of pressure on the mainline kernel and might get things moving there.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#28
post #19

It always make me sad when I hear BSDs are underfunded, OpenBSD was about to "turn off the lights", FreeBSD was in sersious problems before they got 1M$ donation from WhatsApp. Heartbleed bug in OpenSSL? They also didn't have enough (full time) developers to even review the code. Now grsecurity makes me feel bad about it. Everyone uses their software, firewalls, servers, email serves, openssl is everywhere, corporate…

FreeBSD did not have serious problems, they were doing reasonably well. Clearly they can do more now but that is definitely not true.

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#29
post #19

It always make me sad when I hear BSDs are underfunded, OpenBSD was about to "turn off the lights", FreeBSD was in sersious problems before they got 1M$ donation from WhatsApp. Heartbleed bug in OpenSSL? They also didn't have enough (full time) developers to even review the code. Now grsecurity makes me feel bad about it. Everyone uses their software, firewalls, servers, email serves, openssl is everywhere, corporate…

Grsecurity's approach is superior to OpenBSD's, but both are acceptable.

FreeBSD is actually behind Linux - it lacks an effective access control framework and did not have ASLR until the latest release. At least they're working on it (TrustedBSD, Capsicum).

Re: Grsecurity Developer Spender's Feelings on the State of Linux Security

#30

Earlier quoted context omitted.

At the time he was against microkernels, QNX had already demonstrated they were faster than the monolithic state of the art. [1] Linux does not have any form of capabilities (maybe Capsicum, but it's not finished). Capabilities are not POSIX capabilities, which redefined a decade-old term, but rather this [2]. The rest is just trite dismissals of the same faux pragmatism that Linus embodies. He's "not interested in t…

I didn't really refer to his massive ego in my previous comment, but this is another facet of his idiocy in my opinion. The signs were there 20 years ago, but now one could say that the adorations and worship of vast number of subordinates and minions have all turned him into a monster, like a caricature of the corrupt Roman emperors. I sure hope some other leading figure emerges and seizes some control over Linux be…

My vote goes to Spender.
Post reply on HN