1 |
On 12/31/11 08:43, "Tóth Attila" wrote: |
2 |
> Isn't it miserable to see, that as time is passing by, more and more |
3 |
> important softwares (java, python, libreoffice, firefox) conflict |
4 |
> with more and more PAX restrictions? I would expect exactly the |
5 |
> opposite. But it seems, that developers become less and less aware |
6 |
> (or care less) about security. |
7 |
> |
8 |
> Nowdays I would rather run libreoffice and firefox in a jail. But I |
9 |
> have no time to set up an environment and grsec policy for it. |
10 |
|
11 |
Heh...better yet; using VMs - with optional hardware assistance. |
12 |
|
13 |
Joanna Rutkowska of <http://theinvisiblethings.blogspot.com/> , who is |
14 |
well-known as an effective white-hat cracker, is developing a "secure" |
15 |
OS she calls Qubes <http://qubes-os.org/Home.html> |
16 |
|
17 |
She's presently using fedora as the Linux source distribution, but |
18 |
there's been a lot of enthusiastic discussion among some of the beta |
19 |
testers about changing to Gentoo |
20 |
<https://groups.google.com/group/qubes-devel/browse_thread/thread/588399cdd43da28c#> |
21 |
and some of these guys seem poised to go for it. |
22 |
|
23 |
Should the switch occur, one would painlessly have hardened Gentoo VMs, |
24 |
managed by a XEN bare-metal hypervisor. |
25 |
|
26 |
In the case of Firefox 9.0 (actually, now Firefox 9.0.1), one could |
27 |
safely continue with Firefox 8.0 in temporary ("disposable") VMs 'til |
28 |
the Gentoo developers (who are volunteers, generously donating personal |
29 |
time) get a chance to address the issue. |