Gentoo Archives: gentoo-dev

From: Tom Wijsman <TomWij@g.o>
To: gentoo-dev@l.g.o
Cc: ago@g.o, toolchain@g.o
Subject: Re: [gentoo-dev] Improve the security of the default profile
Date: Thu, 05 Sep 2013 10:47:13
Message-Id: 20130905124701.2ce1b44d@TOMWIJ-GENTOO
In Reply to: [gentoo-dev] Improve the security of the default profile by Agostino Sarubbo
1 On Thu, 05 Sep 2013 12:13:28 +0200
2 Agostino Sarubbo <ago@g.o> wrote:
3
4 > Hello,
5 >
6 > during an irc debate, me and other people just noticed that the
7 > default profile could use more flags to enhance the security.
8 >
9 > An hint is here:
10 > https://wiki.ubuntu.com/ToolChain/CompilerFlags
11 >
12 > Please argue about what we _don't_ use.
13 >
14 > Note: please CC me in your response.
15
16 What I wonder about here is at which cost this does come, when looking
17 at the fstack-protector then I see that it "emits extra code"; so, now
18 the question is what kind of overhead this causes.
19
20 I am pretty sure security might not be that important on a real time
21 system that perhaps isn't connected to the internet; so, besides making
22 it the default, we might want to introduce the necessary means to turn
23 it off again, by the very least perhaps documentation would suffice.
24
25 Do you intend to discuss that flag or more generally any security flag?
26
27 --
28 With kind regards,
29
30 Tom Wijsman (TomWij)
31 Gentoo Developer
32
33 E-mail address : TomWij@g.o
34 GPG Public Key : 6D34E57D
35 GPG Fingerprint : C165 AF18 AB4C 400B C3D2 ABF0 95B2 1FCD 6D34 E57D

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies