4 ms·
Honestly, most of the concerns are rather superficial. You might want to try HardenedBSD instead of regular FreeBSD though, to get all the exploit mitigation s
by floatboth 9y ago
Honestly, most of the concerns are rather superficial.
You might want to try HardenedBSD instead of regular FreeBSD though, to get all the exploit mitigation stuff.
- tachion 9y agoDon't do that. HardenedBSD is rather a one man project, who's patches have been reviewed and rejected by FreeBSD developers due to bad quality, poor design and lack of cooperation in bringing them to FreeBSD expected standards. It seems like a PR campaign from people who can write some C, but don't have much credibility in writing secure operating systems or production ready code. Beside the quality of the proposed solutions, there was nothing in the FreeBSD project stopping the code from being accepted. Wether the bad ASLR implementation or no implementation is worse, it's up to you to decide, but I'll vote for quality first.
- X86BSD 9y agoI could be wrong but I was under the impression certain sec folks objected to a lot of his patches because they just are not sold on if ASLR really adds any benefit. Or any benefit vs the complexity it adds. Correct me if I’m wrong. I know Theo has bought into it. I just recall in FreeBSD it wasn’t accepted if it really fixes anything.
- empthought 9y agoFYI since a couple weeks ago, all of your comments except this one appear dead. You must have made someone mad.
- jemsa 9y agoYet FreeBSD hasn't done a single thing to improve the current state of exploit mitigations. It doesn't matter how many people are writing code, grsecurity is mainly Spender & pipacs aka PaXTeam yet 14 Linux developers couldn't spot the vulnerabilities they've created by copy pasting and editing code from grsecrutiy. You can't really blame others for trying while FreeBSD hasn't tried a single thing yet.
- tachion 9y agoNo one, at least not me, is blaming him for trying. But he is to be blamed for sending a poorly written and badly designed patch, unwilling to work on it until it meets the quality of the FreeBSD project and then 'forking' FreeBSD, applying these widely criticised patches and making a social campaign of "they don't want to fix security" instead of "they don't want to introduce bad code" what would be much closer to the truth.