Gentoo Archives: gentoo-dev

From: Ciaran McCreesh <ciaranm@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Stack smash protected daemons
Date: Wed, 22 Sep 2004 16:07:44
Message-Id: 20040922170424.26f1253b@snowdrop.home
In Reply to: [gentoo-dev] Stack smash protected daemons by John Richard Moser
1 On Wed, 22 Sep 2004 11:54:55 -0400 John Richard Moser
2 <nigelenki@×××××××.net> wrote:
3 | I believe it would be a good idea to have such a FEATURES or USE flag
4 | on by default in all profiles where SSP is supported. In this manner,
5 | the major targets of security attacks would automatically be
6 | protected; while still allowing the user to disable the protection if
7 | the user desires. Users wanting more protection can simply add
8 | -fstack-protector to CFLAGS, or use Hardened Gentoo.
9
10 Personally, I don't see the point in an ugly hack which occasionally
11 sort of protects you from badly written code... The option's there for
12 anyone who really wants it, but we tend more towards a "turn most things
13 off unless the user asks for them" approach, hence the relatively low
14 number of things turned on in the default USE settings.
15
16 | Any comments? Would this be more suitable as a USE or a FEATURES
17 | setting?
18
19 FEATURES, not USE.
20
21 --
22 Ciaran McCreesh : Gentoo Developer (Sparc, MIPS, Vim, Fluxbox)
23 Mail : ciaranm at gentoo.org
24 Web : http://dev.gentoo.org/~ciaranm

Replies

Subject Author
Re: [gentoo-dev] Stack smash protected daemons Elfyn McBratney <beu@×××.org>
Re: [gentoo-dev] Stack smash protected daemons Marius Mauch <genone@g.o>
Re: [gentoo-dev] Stack smash protected daemons John Richard Moser <nigelenki@×××××××.net>
Re: [gentoo-dev] Stack smash protected daemons Daniel Goller <morfic@g.o>