1 |
I'm aware of Qubes. But as long as it is based on rpms, I won't make the |
2 |
time investment necessary for studying it. |
3 |
It would be good if Joanna would realize, that a source based rolling |
4 |
distro is easier to handle for their purposes. I haven't aware this was |
5 |
addressed on the mailing list. BTW Laszlo Zrubecz is a Hungarian guy. But |
6 |
I don't know him. |
7 |
|
8 |
Handling the firefox situation at the ebuild level is pretty simple, since |
9 |
we have pax-marking available now for use. The real solution would be to |
10 |
teach upstream about security and proper memory handling. As it was |
11 |
mentioned by paxteam and others as well. Like it is not just erroneous |
12 |
from the security point of view, but the whole concept of fixed address |
13 |
mmap is not correct. |
14 |
|
15 |
It would be good not to think about disposable VMs because of |
16 |
security-blind applications. I still haven't give it up. I hope 2012 will |
17 |
be better! :-) |
18 |
|
19 |
Happy New year: |
20 |
Dw. (Central European Timezone) |
21 |
-- |
22 |
dr Tóth Attila, Radiológus, 06-20-825-8057 |
23 |
Attila Toth MD, Radiologist, +36-20-825-8057 |
24 |
|
25 |
2012.Január 1.(V) 01:39 időpontban 7v5w7go9ub0o ezt írta: |
26 |
> On 12/31/11 08:43, "T?th Attila" wrote: |
27 |
>> Isn't it miserable to see, that as time is passing by, more and more |
28 |
>> important softwares (java, python, libreoffice, firefox) conflict |
29 |
>> with more and more PAX restrictions? I would expect exactly the |
30 |
>> opposite. But it seems, that developers become less and less aware |
31 |
>> (or care less) about security. |
32 |
>> |
33 |
>> Nowdays I would rather run libreoffice and firefox in a jail. But I |
34 |
>> have no time to set up an environment and grsec policy for it. |
35 |
> |
36 |
> Heh...better yet; using VMs - with optional hardware assistance. |
37 |
> |
38 |
> Joanna Rutkowska of <http://theinvisiblethings.blogspot.com/> , who is |
39 |
> well-known as an effective white-hat cracker, is developing a "secure" |
40 |
> OS she calls Qubes <http://qubes-os.org/Home.html> |
41 |
> |
42 |
> She's presently using fedora as the Linux source distribution, but |
43 |
> there's been a lot of enthusiastic discussion among some of the beta |
44 |
> testers about changing to Gentoo |
45 |
> <https://groups.google.com/group/qubes-devel/browse_thread/thread/588399cdd43da28c#> |
46 |
> and some of these guys seem poised to go for it. |
47 |
> |
48 |
> Should the switch occur, one would painlessly have hardened Gentoo VMs, |
49 |
> managed by a XEN bare-metal hypervisor. |
50 |
> |
51 |
> In the case of Firefox 9.0 (actually, now Firefox 9.0.1), one could |
52 |
> safely continue with Firefox 8.0 in temporary ("disposable") VMs 'til |
53 |
> the Gentoo developers (who are volunteers, generously donating personal |
54 |
> time) get a chance to address the issue. |
55 |
> |
56 |
> |
57 |
> |
58 |
> |
59 |
> |