Gentoo Archives: gentoo-hardened

From: 7v5w7go9ub0o <7v5w7go9ub0o@×××××.com>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Re: Intel quad core and hardened
Date: Tue, 01 Apr 2008 16:52:46
Message-Id: 47F26851.8080408@gmail.com
In Reply to: Re: [gentoo-hardened] Intel quad core and hardened by dexters84
1 dexters84 wrote:
2
3 > I've setup a hardened gentoo on the following settings:
4 >
5 > CHOST="x86_64-pc-linux-gnu"
6 > CFLAGS="-march=nocona -O2 -pipe"
7 >
8 > My cpu is quad core xeon + 4 GB ram, it is working without any problems.
9 > While it is perfectly doable to create a hardened setup for mentioned
10 > CPU i think that for a desktop machine it makes little sense.
11 >
12 > The choice is, as always with gentoo, up to You.
13
14 Thanks for the reply, dexter!
15
16 Another question, please. FWICT, a year ago
17 http://www.irqbalance.org/documentation.php in userland was generally
18 considered better than the in-kernel algorithm.
19
20 Do you think that is still the case for 2.6.23+?
21
22 If so, IIUC I'd disable the kernel irq balancing algorithm within the
23 kernel!?
24
25 TIA
26
27 (As far as hardened on a desktop is concerned I admit it is a bit
28 non-traditional, but managing one's financial accounts via desktop is
29 non-traditional, and there seems today to be an increasing amount of
30 serious energy directed toward compromising desktops (for financial
31 information or bot service). So a very strong appeal of Gentoo is its
32 hardened sources and the OpenBSD-like chroot jails. It has worked
33 smoothly for me for years now, and I'd simply maintain the current boxes
34 (desktop is copied to the laptop).
35
36 I am on the road a lot, and frequently use open hotspots to conduct
37 business (i.e. a hostile LAN). After one reads of the latest browser,
38 media-streaming, or IM memory attacks, it is reassuring to know that
39 each of my WAN-connected clients is in its own individual, hardened jail
40 (this is GRSecurity, not SELinux - a lot easier for a home user to
41 maintain).
42
43 Heh.. in fact, to make it even farther over the top, I run the browser
44 chroot jails in RamDisk :-) )
45
46
47
48
49
50
51 --
52 gentoo-hardened@l.g.o mailing list