Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Assessing the Tux Strength: Part 2 - Into the Kernel
Date: Fri, 17 Sep 2010 00:05:46
Message-Id: c17934f5d92edbc87bf314fdefbcd9be.squirrel@atoth.sote.hu
In Reply to: Re: [gentoo-hardened] Assessing the Tux Strength: Part 2 - Into the Kernel by Dale Pontius
1 You 'll have to make a compromise. I run hardened gentoo on my laptop.
2 Everyday use requires loosening the security settings here-and-there.
3
4 --
5 dr Tóth Attila, Radiológus, 06-20-825-8057, 06-30-5962-962
6 Attila Toth MD, Radiologist, +36-20-825-8057, +36-30-5962-962
7
8 2010.Szeptember 17.(P) 01:35 időpontban Dale Pontius ezt írta:
9 > On 09/02/10 18:43, Radoslaw Madej wrote:
10 >> Hi Guys,
11 >>
12 >> For anyone interested, I'd like to announce that the second part of my
13 >> comparison between different Linux distros and their security features
14 >> (which
15 >> includes Gentoo Hardened of course! ;) ) can be found here:
16 >> http://labs.mwrinfosecurity.com/notices/assessing_the_tux_strength_part_2_into_the_kernel/
17 >>
18 >> As always - all feedback is appreciated. Also please note that the
19 >> previous
20 >> feedback is not to be forgotten and I shall address these
21 >> ((-fstack-protector
22 >> vs. -fstack-protector-all, cookie strength and prelink) in my fourth
23 >> post :)
24 >>
25 >> Also - congrats to Zorry for becoming the new Gentoo Hardened lead and
26 >> thanks
27 >> for all your support! :)
28 >>
29 > I read this today, too. Quite interesting, but it leaves me asking a
30 > simple question...
31 >
32 > I've been running my servers for years on hardened Gentoo, but I always
33 > figured it would be too problematic for my deskside and laptop machines.
34 >
35 > Is this true? Have things gotten better, and is it perfectly reasonable
36 > to run hardened Gentoo for general purpose use?
37 >
38 > Two problem factors... My family likes YouTube and the like, and for my
39 > job I have to run proprietary binary-only software. (Silicon CAD tools)
40 >
41 > Thanks,
42 > Dale Pontius
43 >