Gentoo Archives: gentoo-hardened

From: "Tóth Attila" <atoth@××××××××××.hu>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Re: hardened-sources & tp_smapi, firefox-9.0 install stucks
Date: Sun, 01 Jan 2012 02:22:48
Message-Id: 107bdce0e1070b19223b17dc68b258ee.squirrel@atoth.sote.hu
In Reply to: [gentoo-hardened] Re: hardened-sources & tp_smapi, firefox-9.0 install stucks by 7v5w7go9ub0o <7v5w7go9ub0o@gmail.com>
1 I'm aware of Qubes. But as long as it is based on rpms, I won't make the
2 time investment necessary for studying it.
3 It would be good if Joanna would realize, that a source based rolling
4 distro is easier to handle for their purposes. I haven't aware this was
5 addressed on the mailing list. BTW Laszlo Zrubecz is a Hungarian guy. But
6 I don't know him.
7
8 Handling the firefox situation at the ebuild level is pretty simple, since
9 we have pax-marking available now for use. The real solution would be to
10 teach upstream about security and proper memory handling. As it was
11 mentioned by paxteam and others as well. Like it is not just erroneous
12 from the security point of view, but the whole concept of fixed address
13 mmap is not correct.
14
15 It would be good not to think about disposable VMs because of
16 security-blind applications. I still haven't give it up. I hope 2012 will
17 be better! :-)
18
19 Happy New year:
20 Dw. (Central European Timezone)
21 --
22 dr Tóth Attila, Radiológus, 06-20-825-8057
23 Attila Toth MD, Radiologist, +36-20-825-8057
24
25 2012.Január 1.(V) 01:39 időpontban 7v5w7go9ub0o ezt írta:
26 > On 12/31/11 08:43, "T?th Attila" wrote:
27 >> Isn't it miserable to see, that as time is passing by, more and more
28 >> important softwares (java, python, libreoffice, firefox) conflict
29 >> with more and more PAX restrictions? I would expect exactly the
30 >> opposite. But it seems, that developers become less and less aware
31 >> (or care less) about security.
32 >>
33 >> Nowdays I would rather run libreoffice and firefox in a jail. But I
34 >> have no time to set up an environment and grsec policy for it.
35 >
36 > Heh...better yet; using VMs - with optional hardware assistance.
37 >
38 > Joanna Rutkowska of <http://theinvisiblethings.blogspot.com/> , who is
39 > well-known as an effective white-hat cracker, is developing a "secure"
40 > OS she calls Qubes <http://qubes-os.org/Home.html>
41 >
42 > She's presently using fedora as the Linux source distribution, but
43 > there's been a lot of enthusiastic discussion among some of the beta
44 > testers about changing to Gentoo
45 > <https://groups.google.com/group/qubes-devel/browse_thread/thread/588399cdd43da28c#>
46 > and some of these guys seem poised to go for it.
47 >
48 > Should the switch occur, one would painlessly have hardened Gentoo VMs,
49 > managed by a XEN bare-metal hypervisor.
50 >
51 > In the case of Firefox 9.0 (actually, now Firefox 9.0.1), one could
52 > safely continue with Firefox 8.0 in temporary ("disposable") VMs 'til
53 > the Gentoo developers (who are volunteers, generously donating personal
54 > time) get a chance to address the issue.
55 >
56 >
57 >
58 >
59 >

Replies

Subject Author
Re: [gentoo-hardened] Re: hardened-sources & tp_smapi, firefox-9.0 install stucks Wirt Wolff <zug6illa@×××××.com>