3 ms·
Given there's an actual non-zero performance impact on ASLR, I wonder if there's any remaining benefit to have it (also from a maintenance perspective).
by usernam 10y ago
Given there's an actual non-zero performance impact on ASLR, I wonder if there's any remaining benefit to have it (also from a maintenance perspective).
- baq 10y agothis result has brought the attack surface from impractically small to maybe hard but definitely reasonable; disabling ASLR altogether means reasonable becomes easy.
- usernam 10y agoGiven this attack can be run within large userspace programs that are run directly from the network (js via browsers, or within VM boundaries), I don't think that "reasonable" would be the right word. The constraints are pretty small in these scenarios. Once a POC is released it becomes widespread pretty quickly. There's no special size/constraint that effectively stops this attack being run on a large scale.
- staticassertion 10y agoThe non-zero performance impact on ASLR is basically 0, and impacts link-time performance more than anything else, which most devs should not care about. So before you start going for the tiniest of microoptimizations maybe profile. Yes, there is absolutely reason to use ASLR. This attack assumes that an attacker can get the target program to eval arbitrary code. This is not something most programs do. If you are remotely exploiting a vulnerable SSH, or some service, this attack provides nothing to you. ASLR is still very effective for this use case. This is why I find this paper so frustrating.