3 ms·
Linux being secure is a fallacy too. Spender talks about it for a long time: https://grsecurity.net/~spender/interview_notes.txt https://grsecurity.net/~spende
by i4k 10y ago
Linux being secure is a fallacy too.
Spender talks about it for a long time:
https://grsecurity.net/~spender/interview_notes.txt https://grsecurity.net/~spender/interview_notes.txt
Linux developers fix security bugs in irresponsible ways, saying nothing about the attack vector or CVE's involved. Sometimes multiple vulnerabilities are addressed in the same patch, making hard to track the fix.
For more information see the exploit below:
https://grsecurity.net/~spender/exploits/64bit_dos.c https://grsecurity.net/~spender/exploits/64bit_dos.c
The list of kernel vulnerabilities involving namespaces is bigger each day, as the paper shows, but the industry still uses "container" and "security" in the same quotes.