Gentoo Archives: gentoo-hardened

From: RB <aoz.syn@×××××.com>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] 'paxctl -m bin' everything that complains?
Date: Fri, 23 Jan 2009 04:12:09
Message-Id: 4255c2570901222012w5b79c3a1pc8f214e19b0fe012@mail.gmail.com
In Reply to: Re: [gentoo-hardened] 'paxctl -m bin' everything that complains? by Grant
1 On Thu, Jan 22, 2009 at 20:07, Grant <emailgrant@×××××.com> wrote:
2 > It turns out I need to issue 'paxctl -m
3 > /usr/lib64/mozilla-firefox/firefox' to prevent firefox from crashing
4 > when watching a cnn.com video. Is that a huge security issue?
5
6 That's up to you. In running X and firefox, you've probably made
7 enough compromises that one more isn't going to make that much more of
8 a difference. That said, execution protections (like MPROTECT) are
9 probably some of the more critical ones you're going to have, due to
10 the way most malware works, and turning them off on a browser is
11 probably unwise.
12
13 Security is always a balance of control & usability, choose yours and
14 live with it.