4 ms·
Couldn't they do something that's "repeatably random"? So that in case of a bug, you can extract some information from your kernel on its current randomisation,
by frederikvs 10y ago
Couldn't they do something that's "repeatably random"? So that in case of a bug, you can extract some information from your kernel on its current randomisation, and then another kernel can use this information to repeat your random layout.
E.g. use pseudorandom numbers, store the seed somewhere. In case of a bug, extract that seed, pass it on to the dev, and he'll run his kernel with that seed to reproduce.
- DasIch 10y agoHow do you prevent an attacker from getting the seed? This would just create a possible attack vector that could be used to effectively disable address space randomization.
- frederikvs 10y agoe.g. only root can get access to the seed. Then the attacker would already need to have root, so then you're in huge trouble anyways. And yes, it may be weaker than a full-random solution. But a pseudorandom system that gets accepted is more secure than a full-random system that doesn't get accepted.
- kodroid 10y agoThis would sort of negate the purpose of ASLR, as afaik the whole point is an attacker would not know the mem layout. The very fact its not reproducible is the solution and the problem!
- eeZah7Ux 10y agoNo. If the seed would be made available only in a kernel bug report.
- wyldfire 10y agoYes, that is what frederikvs probably means but access to the seed could become a new weakest link of ASLR. Presumably only available to CAP_SYS_ADMIN/uid 0, but it's worth a great deal of caution in designing the feature that allows determining what the seed was.
- nickpsecurity 10y agoFurther adding to that, the seed could be changed before that bug report was submitted. A dedicated tool with a FSM and minimal privileges does it. That lets us verify it strongly.