4 ms·
"unprivileged namespaces, something I think should be off by default in all Linux distributions given its history of security vulnerabilities." Does anyone kno
by frederikvs 10y ago
"unprivileged namespaces, something I think should be
off by default in all Linux distributions given its history of
security vulnerabilities."
Does anyone know where to find more advice like this? Which features of the kernel to disable in order to be more secure?
- JoshTriplett 10y agohttp://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project#Recommended_settings http://kernsec.org/wiki/index.php/Kernel_Self_Protection_Pro... provides a good list.
- frederikvs 10y agoAwesome, thanks. I had heard of the kernel self protection project, but didn't realise that they'd also maintain such a nice list :-)
- lima 10y agoOr you can use grsecurity, which goes even further: https://grsecurity.net/ https://grsecurity.net/ In fact, many of the KSP patches are inspired by Grsecurity.
- _joel 10y agoWould this vulnerability have been mitigated with default grsec, ooi?
- dmix 10y agoNot sure about this one but there has been more than enough public vulns that grsec was already protecting against before release to justify using it for the security conscious Linux user. Archlinux has packages that make it very easy to use.
- staticassertion 10y agoNote that if you can compile the kernel yourself there are benefits to doing so. It's been a while so I forget the details but grsecurity uses some randomization at compile time, and an attacker with access to the public image would be able to get around those defenses. If you own the seed, and delete it after compilation, an attacker will not be able to bypass those defenses. Naturally you still benefit a ton without those, but the ideal situation involves compiling it.
- staticassertion 10y agoGrsecurity does not allow unprivileged namespaces, so this would only be exploitable by a root user.