1 |
dexters84 wrote: |
2 |
|
3 |
> I've setup a hardened gentoo on the following settings: |
4 |
> |
5 |
> CHOST="x86_64-pc-linux-gnu" |
6 |
> CFLAGS="-march=nocona -O2 -pipe" |
7 |
> |
8 |
> My cpu is quad core xeon + 4 GB ram, it is working without any problems. |
9 |
> While it is perfectly doable to create a hardened setup for mentioned |
10 |
> CPU i think that for a desktop machine it makes little sense. |
11 |
> |
12 |
> The choice is, as always with gentoo, up to You. |
13 |
|
14 |
Thanks for the reply, dexter! |
15 |
|
16 |
Another question, please. FWICT, a year ago |
17 |
http://www.irqbalance.org/documentation.php in userland was generally |
18 |
considered better than the in-kernel algorithm. |
19 |
|
20 |
Do you think that is still the case for 2.6.23+? |
21 |
|
22 |
If so, IIUC I'd disable the kernel irq balancing algorithm within the |
23 |
kernel!? |
24 |
|
25 |
TIA |
26 |
|
27 |
(As far as hardened on a desktop is concerned I admit it is a bit |
28 |
non-traditional, but managing one's financial accounts via desktop is |
29 |
non-traditional, and there seems today to be an increasing amount of |
30 |
serious energy directed toward compromising desktops (for financial |
31 |
information or bot service). So a very strong appeal of Gentoo is its |
32 |
hardened sources and the OpenBSD-like chroot jails. It has worked |
33 |
smoothly for me for years now, and I'd simply maintain the current boxes |
34 |
(desktop is copied to the laptop). |
35 |
|
36 |
I am on the road a lot, and frequently use open hotspots to conduct |
37 |
business (i.e. a hostile LAN). After one reads of the latest browser, |
38 |
media-streaming, or IM memory attacks, it is reassuring to know that |
39 |
each of my WAN-connected clients is in its own individual, hardened jail |
40 |
(this is GRSecurity, not SELinux - a lot easier for a home user to |
41 |
maintain). |
42 |
|
43 |
Heh.. in fact, to make it even farther over the top, I run the browser |
44 |
chroot jails in RamDisk :-) ) |
45 |
|
46 |
|
47 |
|
48 |
|
49 |
|
50 |
|
51 |
-- |
52 |
gentoo-hardened@l.g.o mailing list |