3 ms·
Who are these top security researchers? ASLR on its own is useless but security is about layers there isn't one mitigation to rule em all. But ASLR combined wit
by jemsa 9y ago
Who are these top security researchers?
ASLR on its own is useless but security is about layers there isn't one mitigation to rule em all.
But ASLR combined with other features work very well, the funny part about FreeBSD that you can just apply 90s blog post about smashing the stack and you can exploit with it.
grsecurity code is clean and uses some neat tricks with the C language, most features have been there for at least a decade and recently things like RAP have come along but its all pretty clean.
The problem with upstreaming is that you will have people that think the code is shit or doesn't work properly or all kinds of other stuff and that takes a lot of time that could be spent somewhere else.
About the quality matching the respective project's standards is bullshit because many developers aren't security engineers or have never dealt with exploit mitigation's and instantly think/say the code is shit, biggest reason why Linux will never get actual important features from grsecurity because it takes lots of time and developers that actually understand what they are doing.
FreeBSD just doesn't have those developers and neither has Linux, now you know why out of tree patches just work for this kind of stuff.
Microsoft seems to take the upper hand in exploit mitigation's at the moment.