3 ms·
Linux with grsecurity is a pretty obvious alternative. There are distros which include grsecurity patched kernels in their repo (or use it by default) although
by ryuuchin 10y ago
Linux with grsecurity is a pretty obvious alternative. There are distros which include grsecurity patched kernels in their repo (or use it by default) although going this route over a self-compiled one does loose out on a few security features.
Some grsecurity features are supersets of the features you listed such as the W^X protections (which I might add have been in PaX for quite some time now). While the situation certainly isn't perfect with getting more packages using PIE at least a number of important packages are now built with that by default. Arch Linux compiles all packages in its repo's with stack protection AFAIK and at least on Arch it's very easy to recompile things to suit your (performance) needs/threat model.
Perhaps OpenBSD offers more of these compiled protections by default in its base/ports but you can still get these options on Linux if you're willing to put a little effort in or use the right distro for your needs.
OpenBSD is less of an obvious choice when you look at what you can do with grsecurity if you put a bit of effort into it both on the side of grsecurity (RBAC) and setting up your distro. You can't just wave your hand and dismiss grsecurity because you believe it to be non-standard/non-upstream or somehow incomprehensible/complicated. It's not about what's enabled by default, it's about how much security/protection/defense in depth I can get from it and arguably you get more from Linux w/grsecurity.
- ben_bai 10y agoThe point is "optional security is bad security" because when stuff doesn't work it gets turned off. So _nobody_ turns those things on. In OpenBSD all the mitigations are enabled all the time, and with pledge beeing the responsibility of the coder, no extra effort needed from the sys admin.
- ryuuchin 10y agoI was just trying to make a point that OpenBSD is not always the best choice for all possible use cases to expand upon tptacek's post a little. In may be for someone uninformed or lazy but my argument is if you're willing to put in a little effort you can get a system which is arguably better from a security and defense in depth standpoint than OpenBSD. There are obvious benefits to both but I don't think that grsecurity is something which can be dismissed as easily as saying nobody uses it.