9 ms·
Grsecurity Developer Spender's Feelings on the State of Linux Security
- antocv 11y agoWell there is no Linux security. L4 provides that.
- nickpsecurity 11y agoUpvoting you because the first statement is right: there is no Linux security. Why? Security at a minimum requires a formal policy of what it's to achieve along with evidence the design meets that policy. Linux never had it. It's track record for flaws goes way in the opposite direction, too. So, it's insecure by default until proven otherwise and that might not even be possible due to complexity. Combinations of micro/sep kernels and paravirtualized Linux... from L4 projects to commercial like LynxSecure... at least have a start on a security via isolation argument. A start...
- _yy 11y agoThis is the Washington Post interview he wrote this for: http://www.washingtonpost.com/sf/business/2015/11/05/net-of-insecurity-the-kernel-of-the-argument/ http://www.washingtonpost.com/sf/business/2015/11/05/net-of-... Source: https://twitter.com/grsecurity/status/662393322699415554 https://twitter.com/grsecurity/status/662393322699415554 > Very fair article on the topic of Linux security: [...] … Was a pleasure talking with @craigtimberg
- gozo 11y agoThe comments in the HN submission must be some new record in middlebrow dismissals. https://news.ycombinator.com/item?id=10515817 https://news.ycombinator.com/item?id=10515817
- _yy 11y agoAstonishingly so, since it's actually a very good article. Only one or two (minor) flaws in a long article about a technical subject, written by a journalist, is a good tally.
- epistasis 11y agoI think the article did a terrible disservice to the critics: there's lots of hot air in the article but little devoted to the meat of the critics complaints. Meanwhile, Linus' simple rebuttal is given full time, and seems completely reasonable. It wasn't until I read this post that I felt that the Linux maintainers may be doing some things wrong.
- heinrich5991 11y agoSee also this story: https://grsecurity.net/announce.php https://grsecurity.net/announce.php.
- jakeogh 11y agoThe Gentoo Hardened Project makes using grsec/PaX relatively easy. https://wiki.gentoo.org/wiki/Project:Hardened https://wiki.gentoo.org/wiki/Project:Hardened
- dfc 11y agoAnyone that is curious about grsec and comfortable installing a gentoo overlay would have no problem installing grsec on their own; especially if gentoo was not their normal distro. You are not doing anyone any favors by making grsec look like a Sisyphean task without gentoo.
- riffraff 11y agoI used to run mandrake many years ago, and there was a -grsec kernel available in their package repository, and it just worked.
- _yy 11y agoArch Linux has a working out-of-the-box config too. The guy who contributed it to Arch Linux is Daniel Micay, who was also quoted in the WaPo article.
- meirelles 11y agoI used to be a security freak guy. Using the Gentoo Hardened, GRSecurity PaX/RBAC, customized ACLs, etc. IMHO is a high-quality piece of software, very polished and well-designed... I'm a Ubuntu guy today. For my small business, such level of security is too much time consuming, drawing me back. It's kinda sad.
- antocv 11y agoSame here. I used to make my own Linux distribution, from scratch, with Grsecurity, PaX/RBAC for everything. Then it wasnt so usable, when I needed new packages/software, or upgrades, compiling was tiresome, and I didnt know how to make a package manager, or how to automate everything. I assumed somebody else would do it, a big multi billion dollar company perhaps, since I was just 16 year-old doing that over a summer, they would do better, right? Oh how sad. Nobody really cares about security. Since, enterprises just use lawyers instead of security.
- digi_owl 11y agoMother of all pissing matches...
- zby 11y agoThat looks like a political problem. Maybe the state should fund security for its citizens - maybe we need some new kind of institutions to do this.
- pjf 11y ago> The industry is entirely broken in terms of what it values. Couldn't agree more. I feel that we, as entire IT industry, have failed to provide robustness, security, and privacy after dozens of years of development of Internet technologies. Just take the recent vulnerabilities in Android and iPhones, used everyday by millions of people worldwide. How could that happen after so many billions of dollars invested in the development of the major technology used nowadays? We failed miserably and don't even understand the root problems. Of course, completely different thing is functionality: here we've seen tremendous improvements over the years - which is very positive - but that's another story.
- fulafel 11y agoI think Google has understood the systemic security problems in Android pretty well since the beginning, but adopted a typical data driven approach: gather data, and when/if phones start getting compromised start figuring out what countermeasures are cost effective.
- mtanski 11y agoI wouldn't agree with the statement. The Android app store is filled with apps that steal user data and malicious apps. It only get cleaned up when somebody does some research and tracks things down and it ends up in the press. Or maybe that it's just cost effective to have others do the work for you?
- NickHaflinger 11y agoI would think that everyone here agrees that 'computer' security is in a state of turmoil. Is it possible to design a computing system that fails-safe in the event of a bug in a component, instead of opening the entire system up to exploits. Fails Safe as in the process does nothing or restricts the targeted surface area of the malware.
- pixl97 11y ago>A fail-safe or fail-secure device is one that, in the event of a specific type of failure, responds in a way that will cause no harm, Key statement "Specific type of failure". In theory any particular piece of large software has tens of thousands of fail safes in it all ready. For example, when you send an oversized buffer to an application with input checking it does not explode in a ball of flame (unlike programs from the '90s) and warns you about the problem. But that is where the analogies break down between mechanical items and software, software is far more connected internally than almost all other machines are.
- nickpsecurity 11y agoThere were systems that did that all the way down to hardware in the 1960's with many more since: https://www.schneier.com/blog/archives/2014/04/dan_geer_on_hea.html https://www.schneier.com/blog/archives/2014/04/dan_geer_on_h... Market rejected them because they cost a bit more or didn't have highest, raw performance. Such short-sightedness means most done exist any more in any turn-key form. Many of the modifications are straight-forward enough that even academics are prototyping them and porting Linux/FreeBSD to them. https://news.ycombinator.com/item?id=10522742 https://news.ycombinator.com/item?id=10522742 Mainstream just refuses to learn or adopt proven methods of the past. They use every justification in the world even when the labor is free (FOSS) with someone only asking to use the minimal of proven techniques. Market rarely buys the stuff outside very limited sales of some robust appliances: see Aesec's GEMSOS stuff, SAGE Guard on XTS-400, Nexor Mail Guard (on XTS-400), Green Hill's INTEGRITY-178B OS w/ virtualization, Mikro-SINA VPN on L4, Secure64's SourceT OS for DNS, Sentinel's HYDRA firewall (uses INTEGRITY), and so on. Social, political, and economic problems rather than technical. I see no end to it outside continued sales and development of niche solutions. Note: The things I referenced in last paragraph are either still on the market w/ descriptions available via Google or at least have papers in reach. I left out tons of good stuff that's no longer around or just a prototype. Happy Googling and learning. :)
- vezzy-fnord 11y agoAye, too many people have this defeatist attitude that since perfect security will never be possible, therefore the only valid solution is reactive security (bug-patch cycles). Patch dependence is considered too entrenched for making some changes like replacing ambient authority with capabilities, using failure-oblivious computing [1] to redirect invalid reads and writes, using separation kernels, information flow control, proper MLS [2], program shepherding for origin and control flow monitoring [3] and general fault tolerance/self-healing [4]. I used to look up to Linus Torvalds as many did, but am increasingly beginning to see him as a threat to the advancement of the industry with his faux pragmatism that has led him to speak out against everything from security to microkernels and kernel debuggers. [1] https://www.doc.ic.ac.uk/~cristic/papers/fo-osdi-04.pdf https://www.doc.ic.ac.uk/~cristic/papers/fo-osdi-04.pdf [2] http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.52.366&rep=rep1&type=pdf http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.52.... [3] https://www.usenix.org/legacy/events/sec02/full_papers/kiriansky/kiriansky.pdf https://www.usenix.org/legacy/events/sec02/full_papers/kiria... [4] https://www.cs.columbia.edu/~angelos/Papers/2007/mmm-acns-self.pdf https://www.cs.columbia.edu/~angelos/Papers/2007/mmm-acns-se...
- jpgvm 11y agoI wouldn't be so harsh. Linus thinks and works in the here and now. He is neither interested in the theoretical or bothered by what theoretical people have to say about him. He ships code that works and works well and generally speaking has a good security track record compared to many userspace systems (Adobe Flash anyone?). At the time he was against microkernels it would be fair to say monolithic kernels did definitely have (and continue to have) performance advantages over microkernel architectures. Have things changed? Somewhat. Some of how OS kernels are used has changed and that has made microkernels more attractive again. I feel the rest of your argument just feels like the jab at Linus is tacked on though because he doesn't seem to be against capabilties system. (infact the kernel has what? 3 capabilities systems?) Nor does he seem against forms of multi-level security or program shepherding. So maybe those weren't meant to be directed at him. Either way I just wanted to say that people should give him some slack, his job isn't to please security zealots but to ship software all of us use and many of us depend on for our livelihood in a timely and reliable manner.
- akerro 11y agoIt always make me sad when I hear BSDs are underfunded, OpenBSD was about to "turn off the lights", FreeBSD was in sersious problems before they got 1M$ donation from WhatsApp. Heartbleed bug in OpenSSL? They also didn't have enough (full time) developers to even review the code. Now grsecurity makes me feel bad about it. Everyone uses their software, firewalls, servers, email serves, openssl is everywhere, corporate/bank cluster without BSD or Linux with grsecurity is unimaginable. I recently started donating to opensource project I use everyday. I realised how little they ask for, F-Droid, I easily doubled their BTC found used to cover server maintenance, LibreOffice asks for 3EURO donation by default (also BTC)! OpenBSDFundation asks for 10$ per month. https://grsecurity.net/contribute.php https://grsecurity.net/contribute.php Edit: I also found a nice way how to donate to Tor, there is a site https://oniontip.com/ https://oniontip.com/ where you can donate others for running Tor nodes, one of two top 200nodes has WikiLeaks BTC address, another one goes to my wallet and I send it back to TorProject. I had enough free resources, I used them :)
- c0nfused 11y agoMost of us can afford to pay it too. That's the real tragedy. All of us should consider doing something similar, allocate a couple $ a month and give it to people who make our lives/jobs easier or better.
- CaptSpify 11y ago> Most of us can afford to pay it too. That's the real tragedy. I think the hardest part for me is: I use soooooo much open-source software, that I can't contribute to all of them. Don't get me wrong, I should contribute more than I do, and I'm not excusing myself, but it's a legitimate problem. I'm sure people smarter than me have debated models for this, but I still don't think we have a good answer.
- shermanyo 11y agoPlease, please donate to the library developers. Scan the dependencies for some of your favourite packages and see if there's anything common to a few that might not be obvious. SDL backs so many things, for example, but rarely gets called out.
- fulafel 11y agoGrsecurity languishes in (relative) obscurity because no distribution ships it. I know several people who know about it and would pick the option if it was distro-supported. If you don't get automatic updates it's a non-starter. Popularity in distros would put a lot of pressure on the mainline kernel and might get things moving there.
- Tepix 11y agoPerhaps the way to push security into the industry is to use consumer's rights to their full capacity. In the EU if you buy something, you get 6 months of warranty and 24 months of implied warranty. If you buy an Android phone and stop getting updates after 18 months and there is a new security hole, you should return the phone to your dealer and demand your money back. After all, it's relatively easy to prove that the defect (the security hole) was already present when you bought the phone. The dealer must fix the defect. If he can't, he must take back the article. He will then complain to the manufacturer. The pressure from these complaints hopefully lead to a change of behaviour by the manufacturers (i.e. provide two years of security updates, for example, even if you buy a new phone that's already been available for a year or two).
- 72deluxe 11y agoThat's a very interesting point, and a good idea! It does put the onus on us as developers to ensure we do a good job and get it right from the beginning, which can only be a good thing. The plan for allowing a device to be free from defects for two years since date of purchase is good; since date of announcement is practically worthless, unless companies start announcing products and then waiting a year to release to shorten their support time?
- arca_vorago 11y agoI've been follow grsec for a while now, and I really like the honesty around it. They admit what they are and aren't good at, and as for the product itself (grsec), it has become my go to hardening system for the kernel over SELinux (I know you can combine the two, I don't though). Combined with other measures I think I am doing a pretty good job in balancing out the usability security scale. If you haven't taken the time to learn grsec, you will thank yourself later if you do. Keep in mind though there was some recent drama with some people/companies not properly attributing grsec, so you want to use current instead of stable imho. Alpine linux has grsec build in, gentoo has some good guides, and so does arch, but I tend to add it to debian. As far as the state of linux/kernel security, I blame one thing in particular, and that is complexity and amount of code. The many eyes theory has a fault, in that it assumes a lot of people will look at the code and with enough people the bugs (security bugs) will be found. Well the problem is that the linux kernel is now at 10 million+ loc. So even with a shitton of people digging through the code, lots of stuff is going to get missed, and the real problem is that there are a lot less people looking at the code than we all want to think. I think the primary way we will be able to move to security in the future is in efforts to refactor and reduce complexity of code in general, along with working on making it easier to read (or better commented). This is one reason why I find minix 3 to be a very interesting project, at <10k loc.
- armitron 11y agoGet used to the Linux situation cause it's not going to change I think. The "many eyes" theory is downright stupid, because guess what, there are few if any eyes. The eyes that are many are on the attacker side, extremely skilled individuals who have cut their teeth on the kernel for 15+ years. On the defender side, apart from Google project zero (who are not just focusing on the linux kernel) and a few stray individuals, there is nobody looking for vulnerabilities in the kernel in order to make them public. As far as complexity goes, Linus knows all of that which is why he's playing "catch the baby" or "throw the hot potato". I called him maliciously stupid in a previous comment and I think that's a fair characterization. He's not simply stupid, he knows the stakes and the sad state of affairs in the kernel (complexity, 0 security mindset, archaic architecture) and he sees the options available to him: + Make security top priority (as Microsoft did 10 years ago) which will expose him as a fool for his past mindset since that will amount to him admitting that he was dead wrong all these years. I don't think he has it in him to do this, he's too much of an egomaniac now. It will also expose most of the kernel maintainers and developers as total incompetents when it comes to writing secure code and slow the pace of development. + Let others solve the problem. This is where Grsecurity/PaX comes in. That would necessitate him releasing a lot of control over the kernel into 3rd parties, since the best parts of Grsecurity are pretty intrusive and touch a lot of kernel components. I don't think he's willing to do that either. + Do nothing and deal with the problem by making idiotic statements of the sort "If you care about security, don't connect Linux to the Internet" or "insulate the kernel by adding layers of security such as sandboxes ...". In sort, he's saying it's not his problem STFU and deal with it yourself. These comments are idiotic because any sort of security person knows that you can't build a fortress on shifting and rotting foundations. You can pile as many sandboxes and intrusion detection systems you want, but they can all be bypassed if the kernel is weak. So, to summarize, he knows he has a clusterfuck in his hands due to decades of development with 0 security mindset and he's simply not willing to own up to it. He's throwing the hot potato to us and tries to shift awareness and focus away from the part he's directly responsible for.
- forgottenpass 11y agoThere's no real leadership in Linux as far as security goes from within the kernel community itself. I'm beginning to get the impression this (in general, not just for Linux) is because the talented security folks rather just do the fun parts. It'd be really awesome if more security conscious people were like the OpenBSD developers and worked on products, not just security. I got into software through security. Getting a dump of my high school's faculty and staff password database was my first high and I chased it for years. My current job is in engineering where security is part of, but not all of, my focus. Since taking on this role, I've started feeling alienated participating in the "security community." Work isn't always fun in the moment, work is sometimes just work. There seems to be a gap between how much work the "security community" wants to be able to push on the rest of the open source developer's plate, and how much those developers are willing to take. Security already (rightly) gets a shortcut over a lot of things, but it takes man-hours to make security happen. Why can't it be the security guys? If spender doesn't want to send his kernel patches through the same review and legal processes the rest of us do, that's his problem. Why doesn't he stand up and become that security leadership in the kernel? Of course the submission process could be better, and of course he's not going to get everything he wants from the other maintainers right away... because it's work, and work isn't always fun.
- deleted 11y ago[deleted]
- gozo 11y agoTalented security folks, especially those that can engineer security rather than penetration testing, have so many opportunities that fighting an uphill battle on mailing lists just isn't very attractive.
- forgottenpass 11y agoThat's part of my point. As long as the work is "someone else's problem," will it ever get done? If other opportunities are there for someone with a security skillet, what makes a libfoo maintainer become skilled enough to make the most secure libfoo possible, but also stay on libfoo? Does saying "security is important" mean that security is important, or does it means "have my skillset, and also do the busywork someone with my skillset is able and happy to ignore?"
- grandinj 11y agoThere is no monolithic upstream organization. The real problem is that it's really hard work to upstream code, particularly when it touches core parts of the kernel. Look how long it took to get other invasive stuff like tickless or preempt RT. But it got done, it just took time and patience. And insulting the upstream people like this doesn't make your job any easier.
- rodgerd 11y ago> And insulting the upstream people like this doesn't make your job any easier. The upstream people are pretty wedded to the idea that throwing insults is a reasonable response to frustration with poor behaviour. They do not have any legs to stand on re: hurt feelings.