New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

(Kernel) hardening: Use PaX or Grsec #2345

Closed
rugk opened this Issue Sep 29, 2016 · 5 comments

Comments

Projects
None yet
6 participants
@rugk

rugk commented Sep 29, 2016

If you did not know already: You have been featured by Snowden. 🎉

So this issue is about a response by another user:

solation is one thing, memory corruption prevention is another. You might need PaX/Grsec-based OS, @subgraph ?

https://twitter.com/citypw/status/781497609298989056

So from quickly searching this issue tracker, it seems you do not use any kernel hardening features. What do you think about adding them?

The user also mentions another OS. I think you can certainly get inspiration from the competition. 😄

@ag4ve

This comment has been minimized.

Show comment
Hide comment
@ag4ve

ag4ve Sep 30, 2016

I'll preface my liking this idea by saying I've never run PaX on Xen. There
might also be kernel version issues since they only release long-term
support kernel patches (there's a blog post about why - you pay for the
other versions). If neither of those are blockers - I would love to see
this.

On Sep 29, 2016 2:02 PM, "rugk" notifications@github.com wrote:

If you did not know already: You have been featured by Snowden. 🎉

So this issue is about a response by another user:

solation is one thing, memory corruption prevention is another. You might
need PaX/Grsec-based OS, @subgraph https://github.com/subgraph ?

https://twitter.com/citypw/status/781497609298989056

So from quickly searching this issue tracker, it seems you do not use any
kernel hardening features. What do you think about adding them?

The user also mentions another OS https://subgraph.com/. I think you
can certainly get inspiration from the competition. 😄


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
#2345, or mute the thread
https://github.com/notifications/unsubscribe-auth/ABNnP1BsJwAK3CvpBfgngxS9qpcEHEtbks5qu_1EgaJpZM4KKS7P
.

ag4ve commented Sep 30, 2016

I'll preface my liking this idea by saying I've never run PaX on Xen. There
might also be kernel version issues since they only release long-term
support kernel patches (there's a blog post about why - you pay for the
other versions). If neither of those are blockers - I would love to see
this.

On Sep 29, 2016 2:02 PM, "rugk" notifications@github.com wrote:

If you did not know already: You have been featured by Snowden. 🎉

So this issue is about a response by another user:

solation is one thing, memory corruption prevention is another. You might
need PaX/Grsec-based OS, @subgraph https://github.com/subgraph ?

https://twitter.com/citypw/status/781497609298989056

So from quickly searching this issue tracker, it seems you do not use any
kernel hardening features. What do you think about adding them?

The user also mentions another OS https://subgraph.com/. I think you
can certainly get inspiration from the competition. 😄


You are receiving this because you are subscribed to this thread.
Reply to this email directly, view it on GitHub
#2345, or mute the thread
https://github.com/notifications/unsubscribe-auth/ABNnP1BsJwAK3CvpBfgngxS9qpcEHEtbks5qu_1EgaJpZM4KKS7P
.

@mfc

This comment has been minimized.

Show comment
Hide comment
@mfc

mfc Oct 3, 2016

Member

thanks for opening this issue. for the past year we have tried convincing the subgraph team to work on this (including getting funding for them to do it) by creating subgraph templates for Qubes but they aren't interested. so I think it's worthwhile to track this effort and look elsewhere for potential implementers.

Member

mfc commented Oct 3, 2016

thanks for opening this issue. for the past year we have tried convincing the subgraph team to work on this (including getting funding for them to do it) by creating subgraph templates for Qubes but they aren't interested. so I think it's worthwhile to track this effort and look elsewhere for potential implementers.

@mfc

This comment has been minimized.

Show comment
Hide comment
@mfc

mfc Mar 8, 2017

Member

just to update, the coldkernel team is working on this, see their blogpost and progress:

https://coldhak.ca/blog/2016/12/12/coldkernel-qubes-1.html
https://github.com/coldhakca/coldkernel/issues/35

Member

mfc commented Mar 8, 2017

just to update, the coldkernel team is working on this, see their blogpost and progress:

https://coldhak.ca/blog/2016/12/12/coldkernel-qubes-1.html
https://github.com/coldhakca/coldkernel/issues/35

@marmarek

This comment has been minimized.

Show comment
Hide comment
@marmarek

marmarek Sep 10, 2017

Member

Grsec is dead (at least as an open source project), so it doesn't apply anymore.

Member

marmarek commented Sep 10, 2017

Grsec is dead (at least as an open source project), so it doesn't apply anymore.

@marmarek marmarek closed this Sep 10, 2017

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment