"Protection from zero-days" -- how can you make a claim like this?
CopperheadOS: A hardened open-source operating system based on Android
21–30 of 105 posts
Re: CopperheadOS: A hardened open-source operating system based on Android
#22Earlier quoted context omitted.
I'm not affiliated with Copperhead at all, but I am familiar with the sorts of techniques they are using. Exploit mitigations, such as Address Space Layout Randomization, Control-Flow Integrity, Fine-grained Randomization, etc. provide a layer of hardening to make exploitation of a source code vulnerability harder, or even not possible on the protected device. The bug (zero-day) still exists, it's just not as exploit…
ASLR is already a part of pretty much every current operating system ( save FreeBSD-RELEASE )
Re: CopperheadOS: A hardened open-source operating system based on Android
#23This project seems interesting but largely impractical until a truly independent FOSS app store exists with a wide selection + security track record as good as Google Play or iTunes. I don't see how it gets there with such a narrow hardware selection.
Do they have great security track records? I know a lot of the integrations like games into their systems are terribly insecure.
Re: CopperheadOS: A hardened open-source operating system based on Android
#24This is a hoenypot for the NSA
Re: CopperheadOS: A hardened open-source operating system based on Android
#25"Protection from zero-days" -- how can you make a claim like this?
Re: CopperheadOS: A hardened open-source operating system based on Android
#26This project seems interesting but largely impractical until a truly independent FOSS app store exists with a wide selection + security track record as good as Google Play or iTunes. I don't see how it gets there with such a narrow hardware selection.
> security track record as good as Google Play or iTunes Do they have great security track records? I know a lot of the integrations like games into their systems are terribly insecure.
Re: CopperheadOS: A hardened open-source operating system based on Android
#27Earlier quoted context omitted.
I'm not affiliated with Copperhead at all, but I am familiar with the sorts of techniques they are using. Exploit mitigations, such as Address Space Layout Randomization, Control-Flow Integrity, Fine-grained Randomization, etc. provide a layer of hardening to make exploitation of a source code vulnerability harder, or even not possible on the protected device. The bug (zero-day) still exists, it's just not as exploit…
ASLR is already a part of pretty much every current operating system ( save FreeBSD-RELEASE )
Re: CopperheadOS: A hardened open-source operating system based on Android
#28Earlier quoted context omitted.
I'm not affiliated with Copperhead at all, but I am familiar with the sorts of techniques they are using. Exploit mitigations, such as Address Space Layout Randomization, Control-Flow Integrity, Fine-grained Randomization, etc. provide a layer of hardening to make exploitation of a source code vulnerability harder, or even not possible on the protected device. The bug (zero-day) still exists, it's just not as exploit…
ASLR is already a part of pretty much every current operating system ( save FreeBSD-RELEASE )
Re: CopperheadOS: A hardened open-source operating system based on Android
#29"Protection from zero-days" -- how can you make a claim like this?
Re: CopperheadOS: A hardened open-source operating system based on Android
#30"Protection from zero-days" -- how can you make a claim like this?
Protection from zeroDays Prevents many vulnerabilities and makes exploits harder
So they don't claim to provide immunity from zero days, but