4 ms·
Most security features are disabled by default (PAX, grsecurity, SELinux), and when distributions enable them, they are the first to go when admins encounter pr
by david_draco 5y ago
Most security features are disabled by default (PAX, grsecurity, SELinux), and when distributions enable them, they are the first to go when admins encounter problems.
It is then a chicken-and-egg problem when software fails in secure environments, those failures are not reported/fixed upstream but circumvented, and consequently security cannot be enabled across the board because tools break.
I'd be curious if open source software would become more robust if by default the popular CI systems would enable features that do not cause any false positives but cause crashes in buggy software (memory randomization and read guards, compiler flags for detecting stack overflows).
- totony 5y agoThis is because grsec is proprietary and the state of SELinux policies is very poor. Redhat puts a lot of effort into maintaining their SELinux policy and is the only one that doesn't have too much bugs. PaX should be included, but afaik a lot of what PaX has been doing over the years is being/has been included in mainline.