Gentoo Archives: gentoo-dev

From: "Paweł Hajdan
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Can we get PIE on all SUID binaries by default, por favor?
Date: Fri, 27 Jan 2012 20:14:57
Message-Id: 4F230577.7060602@gentoo.org
In Reply to: Re: [gentoo-dev] Can we get PIE on all SUID binaries by default, por favor? by Fabian Groffen
1 On 1/27/12 8:45 PM, Fabian Groffen wrote:
2 > On 27-01-2012 20:39:24 +0100, "Paweł Hajdan, Jr." wrote:
3 >> If the discussion on this doesn't get conclusive, how about adding the
4 >> question to the Council's agenda?
5 >
6 > Negative from my point of view, this is an issue that the dev-community
7 > can solve themselves without needing a "force" from the Council.
8
9 That's why I said "if the discussion on this doesn't get conclusive". Of
10 course it's much better to have a consensus about that, but in some
11 important cases a tie-breaker can be useful.
12
13 > Just implement it in a way that people can opt-in/opt-out on it.
14
15 We already have an opt-in (hardened profile), and of course it can be
16 implemented in a way which allows opt-out (I even mentioned that).
17
18 The main point is changing the default.
19
20 Another note: "quiet build" default was a part of Council meeting agenda
21 (<http://www.gentoo.org/proj/en/council/meeting-logs/20111213-summary.txt>),
22 so it shouldn't be too surprising that a default important for security
23 is also suggested.
24
25 Again - only if we don't get a consensus here.

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies