Gentoo Archives: gentoo-hardened

From: Kevin Chadwick <ma1l1ists@××××××××.uk>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Security Level: high/server/workstation/virtualization
Date: Fri, 27 Jan 2012 16:29:41
Message-Id: 20120127162519.d8eb8635.ma1l1ists@yahoo.co.uk
In Reply to: [gentoo-hardened] Security Level: high/server/workstation/virtualization by Alex Efros
1 On Fri, 27 Jan 2012 15:26:26 +0200
2 Alex Efros wrote:
3
4 Thanks for the info. In a discussion about malloc flags, it was
5 mentioned on the OpenBSD list that clearing the memory
6 immediately brought little in security as it would be cleared before
7 re-use and if anything could increase the chances of an attacker
8 writing to areas that he wanted to.
9
10 > Core2Duo
11
12 I don't know the details but according to OpenBSDs Theo, the Core2Duo
13 had some major design flaws that intel couldn't fix with microcode with
14 some security implications.

Replies