1 |
On Sun, Dec 11, 2011 at 3:30 PM, Kevin Chadwick <ma1l1ists@××××××××.uk>wrote: |
2 |
|
3 |
> On Sun, 11 Dec 2011 10:18:51 +0000 |
4 |
> Sven Vermeulen wrote: |
5 |
> |
6 |
> > Also consider hardening your system settings-wise. I would appreciate if |
7 |
> you |
8 |
> > take a look at |
9 |
> > http://dev.gentoo.org/~swift/docs/previews/oval/gentoo-xccdf-guide.html. |
10 |
> > With the instructions given, you can even have your system validated (as |
11 |
> far |
12 |
> > as possible) automatically. |
13 |
> |
14 |
> I was expecting to find here what one distro uses which is binary |
15 |
> signature checking upon execution. |
16 |
> |
17 |
> Another thing that I try to do as a better method of TPE which is a |
18 |
> breeze on OpenBSD and sometimes I find myself working against Linux |
19 |
> developers¹ is to make it so that any writeable area of the filesystem |
20 |
> is mounted noexec and mounts have the least priviledges required. |
21 |
> |
22 |
|
23 |
If don't mind my asking, what is it that OpenBSD does differently than the |
24 |
Linux distros that make it so much easier? Do they actually follow the |
25 |
security practices you mentioned in the bug report? |
26 |
|
27 |
|
28 |
|
29 |
> |
30 |
> ¹ "https://bugs.launchpad.net/ubuntu/+source/udisks/+bug/880965" |
31 |
> set as won't fix and also e.g. apt-get expecting /tmp exec. |
32 |
> |
33 |
> |
34 |
Thanks, |
35 |
Matt |
36 |
|
37 |
-- |
38 |
Matthew Finkel |