Live data from Hacker News

Linus: Don't bother with grsecurity. Their patches are pure garbage

spinics.net

21–30 of 172 posts

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#21

I'm an Arch user and I have no idea what's going on with security-focused kernels these days. I was running the grsecurity kernel package but that was recently replaced by a "linux-hardened" package that I had never heard of. Then, a pacman update tonight installed a plain Linux kernel. It's very confusing. Not unexpected for Arch but there is so little on the wiki about this.

The grsecurity patches have been made private. Although they are under the GPL (because they are a derivative work of the Linux kernel), the company that produces grsecurity engages in the unethical (and potentially illegal) business practice of threatening to terminate customer subscriptions if they exercise their right to distribute the patches.

In other words, no customer is going to distribute the patches because they will have wasted money and lost access to updates. This is very reminiscent of free speech chilling effects, and I'm surprised none of the copyright holders in Linux (myself included) have teamed up to sue them.

Long story short, the general community (including distributions) no longer has access to new patches making grsecurity useless for the community.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#22

Linus, and this stubborn attitude of his, is the reason that Linux will always lag behind Windows in kernel security. With the vast security improvements Microsoft are putting into their operating system year on year, it's a shame to see Linux failing to keep up.

>Linux will always lag behind Windows in kernel security

Are you serious about that statement ?

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#23

Linus, and this stubborn attitude of his, is the reason that Linux will always lag behind Windows in kernel security. With the vast security improvements Microsoft are putting into their operating system year on year, it's a shame to see Linux failing to keep up.

A differently sounding username would have at least helped your case. :)

Even if Windows kernel security is more robust, anybody can easily fault you for some form of cognitive bias. I use Windows, therefore Windows is more superior.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#25
post #4

Earlier quoted context omitted.

Can you point to specific times? I want to dig into this more.

Google Linus rant. There are many examples.

Crying wolf requires him to have been wrong (or lied). I think that GP was asking you for evidence of _that_, not of evidence that Linus has ranted in the past.

From memory, I can't recall a time where his ranting was not justified, but he has been wrong a couple of times. Unless I'm missing something blatant, that doesn't constitute "crying wolf" to me.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#26

I'm an Arch user and I have no idea what's going on with security-focused kernels these days. I was running the grsecurity kernel package but that was recently replaced by a "linux-hardened" package that I had never heard of. Then, a pacman update tonight installed a plain Linux kernel. It's very confusing. Not unexpected for Arch but there is so little on the wiki about this.

Because grsecurity make no effort to separate out their patches, it's really hard to upstream them. Sometimes the Arch team get the effort in time, sometimes its overly difficult so you don't get the kernel rolled out by the time an update is available for plain.

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#27
post #23

Linus, and this stubborn attitude of his, is the reason that Linux will always lag behind Windows in kernel security. With the vast security improvements Microsoft are putting into their operating system year on year, it's a shame to see Linux failing to keep up.

A differently sounding username would have at least helped your case. :) Even if Windows kernel security is more robust, anybody can easily fault you for some form of cognitive bias. I use Windows, therefore Windows is more superior.

This is a very weird post. It's like some kind of sith mind trick. "I'd love to know more, but your name implies a connection to the subject matter and we wouldn't want that chuckle taken the wrong way."

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#28
post #10

See Linus' follow-up http://seclists.org/oss-sec/2017/q2/596 for clarification: > They aren't split up, there has never been any effort by you to make them palatable to upstream, and when somebody else dioes try to make them palatable to upstream, you start crying about how people are taking advantage of your work (hah), and try to make them private instead. ... > It's literally less work for people to re-implement t…

And the other guy's reply: http://seclists.org/oss-sec/2017/q2/597

Re: Linus: Don't bother with grsecurity. Their patches are pure garbage

#30
post #21

I'm an Arch user and I have no idea what's going on with security-focused kernels these days. I was running the grsecurity kernel package but that was recently replaced by a "linux-hardened" package that I had never heard of. Then, a pacman update tonight installed a plain Linux kernel. It's very confusing. Not unexpected for Arch but there is so little on the wiki about this.

The grsecurity patches have been made private. Although they are under the GPL (because they are a derivative work of the Linux kernel), the company that produces grsecurity engages in the unethical (and potentially illegal) business practice of threatening to terminate customer subscriptions if they exercise their right to distribute the patches. In other words, no customer is going to distribute the patches because…

> the company that produces grsecurity engages in the unethical (and potentially illegal)

Unethical, probably - illegal, probably not. The GPL dictates what you can do once code hits your hands (or binaries compiled with), it doesn't prevent companies from selling it to you or what contract they do it under.

Post reply on HN