Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: Remove the pic use flag in the hardened amd64 profile.
Date: Sun, 27 Feb 2011 15:33:36
Message-Id: 106429748f5cf067ac6c198fa367e424.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] Re: Remove the pic use flag in the hardened amd64 profile. by Pavel Labushev
1 2011.Február 27.(V) 16:19 időpontban Pavel Labushev ezt írta:
2 > 27.02.2011 21:53, Anthony G. Basile пишет:
3 >
4 >> An example of where it does is an attempt to defeat address space
5 >> randomization by brute force. 32-bit address space is only 4G which is
6 >> not impossibly large for success by brute force while 64-bits is about
7 >> 10^19. A lot harder.
8 >
9 > Another point: UDEREF on x86 is more reliable than on amd64. Choose x86 if
10 > your big concern is to protect the kernel from userland (like, if you use
11 > privilege separation/revocation not just because it looks fancy on paper).
12 >
13
14 More reliable? Interesting. Do you have a link about this?
15 Apart from older systems 32bit will be with us at least because of the ARM
16 architecture.

Replies

Subject Author
Re: [gentoo-hardened] Re: Remove the pic use flag in the hardened amd64 profile. Pavel Labushev <p.labushev@×××××.com>