Gentoo Archives: gentoo-dev

From: Agostino Sarubbo <ago@g.o>
To: gentoo-dev@l.g.o
Cc: Tom Wijsman <TomWij@g.o>, toolchain@g.o
Subject: Re: [gentoo-dev] Improve the security of the default profile
Date: Thu, 05 Sep 2013 10:55:02
Message-Id: 2801841.odtaY24SdY@devil
In Reply to: Re: [gentoo-dev] Improve the security of the default profile by Tom Wijsman
1 On Thursday 05 September 2013 12:47:01 Tom Wijsman wrote:
2 > What I wonder about here is at which cost this does come, when looking
3 > at the fstack-protector then I see that it "emits extra code"; so, now
4 > the question is what kind of overhead this causes.
5
6 We use -fstack-protector-all in the hardened profile, so it is not unknown at
7 all.
8
9 > I am pretty sure security might not be that important on a real time
10 > system that perhaps isn't connected to the internet; so, besides making
11 > it the default, we might want to introduce the necessary means to turn
12 > it off again, by the very least perhaps documentation would suffice.
13 >
14 > Do you intend to discuss that flag or more generally any security flag?
15
16 I just want to point out the thread because other people will have something
17 to say about.
18 --
19 Agostino Sarubbo
20 Gentoo Linux Developer

Replies

Subject Author
Re: [gentoo-dev] Improve the security of the default profile Tom Wijsman <TomWij@g.o>