Gentoo Archives: gentoo-hardened

From: Alex Efros <powerman@××××××××.name>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] RIP hardened-sources
Date: Sun, 30 Apr 2017 11:08:28
Message-Id: 20170430110811.GA11463@home.power
In Reply to: Re: [gentoo-hardened] RIP hardened-sources by Alex Efros
1 Hi!
2
3 On Sat, Apr 29, 2017 at 07:46:10PM +0300, Alex Efros wrote:
4 > Thanks! But isn't this mean you forbid all Linux distributions (including
5 > commercial ones like RedHat) to be GrSec/PaX subscribers (in case they
6 > like to spend some money for it)? I.e. this decision will ensure majority
7 > of Linux systems will never ever have GrSec/PaX
8
9 If no one is replies on this yet because that's sad truth, then may I ask
10 why don't you like to solve this in some way?
11
12 For example, you can continue publishing source of GrSec/PaX versions, but
13 use license which allows using it for free only for personal use and small
14 business (say, less than 10-20 computers) on usual desktop/server PC.
15 This way all server/desktop Linux distributions will be able to include
16 alternative hardened kernel or have alternative hardened variant of
17 overall distribution, but end-user will have to decide is they can use it
18 for free or should subscribe or avoid using it.
19 For Android phones/tablets and embedded devices you can make separate
20 clause in license to let you get some money from Google and companies
21 developing embedded devices if they will like to use GrSec/PaX, without
22 forbidding such a possibility at all (rumours are current subscription
23 options require to limit amount of installations, which is surely doesn't
24 makes sense for Android).
25
26 This way you shouldn't lose any money comparing to current situation,
27 it also solve mentioned before issues when bad companies sell unsupported
28 and modified GrSec variant and use "grsecurity" for marketing own
29 products. Plus you'll continue wide-test your patch with Gentoo Hardened
30 and some other distribution users and have your patch available for any
31 external audit which is always good for security product's karma.
32
33 If there are no good reasons to reject proposed solution and no
34 alternatives to let people continue using GrSec/PaX for personal/small
35 business use, then, yeah, conspiracy theories and three-letter-agencies
36 start coming to mind - just because they wins more than anybody else
37 including yourself if all Linux distributions won't have GrSec/PaX anymore.
38
39 --
40 WBR, Alex.

Replies

Subject Author
Re: [gentoo-hardened] RIP hardened-sources SK <yandereson@××××××.net>