Gentoo Archives: gentoo-hardened

From: pageexec@××××××××.hu
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] hardened workstation - is that worth it?
Date: Fri, 05 Dec 2008 18:11:52
Message-Id: 49396EC9.18770.9B40DB9@pageexec.freemail.hu
In Reply to: Re: [gentoo-hardened] hardened workstation - is that worth it? by Ned Ludd
1 On 5 Dec 2008 at 9:48, Ned Ludd wrote:
2
3 > On Fri, 2008-12-05 at 17:29 +0200, pageexec@××××××××.hu wrote:
4 > > On 25 Nov 2008 at 21:36, Javier Martínez wrote:
5 > >
6 > > > In my opinion getting X-window running is bad in security concerns, by
7 > > > this reasons:
8 > > > - First: PaX should be disable in mprotect terms since Xorg needs it
9 > > > (with it refuse to run) .
10 > >
11 > > - PaX flags: -------x-e-- [/usr/bin/Xorg]
12 > >
13 > > and it works for me... so why do you need to disable MPROTECT on your Xorg?
14 > >
15 >
16 > Could be that other ppl might start hitting that mesa bug..
17
18 if you mean the runtime generated dispatcher stubs and T&L things,
19 i thought they'd affect apps only, not the X server itself...