8 ms·
OpenBSD may soon gain further memory protections: immutable userland mappings
- kyledrake 4y agoThis security tech usually ends up in other platforms too, strongly recommend donating to their work: https://www.openbsdfoundation.org/donations.html https://www.openbsdfoundation.org/donations.html
- bell-cot 4y ago+1...but OpenBSD's webmaster might want to update that page, so it doesn't link to their 2020 Fundraising Campaign. (Their current Campaign - https://www.openbsdfoundation.org/campaign2022.html https://www.openbsdfoundation.org/campaign2022.html ) And "This security tech usually..." is a bit too modest. Just one example - OpenBSD is the origin of OpenSSH, which has been rather widely used for a decade or two now.
- fsckboy 4y agoOpenBSD does great work, but for the record OpenSSH started as a fork of the free SSH program developed by Tatu Ylönen; later versions of Ylönen's SSH were proprietary software offered by SSH Communications Security. https://en.wikipedia.org/wiki/OpenSSH https://en.wikipedia.org/wiki/OpenSSH
- chasil 4y agoRealistically, OpenBSD completely reimplemented protocol 2 themselves. Since nobody uses protocol 1 anymore, very little of the original code from Tatu Ylönen remains in operation with default settings. ps I have had to use the SSH commercial release under VMS, and the compatibilities with OpenSSH are quite unpleasant.
- gigantaure 4y agoi just read that page[1] earlier this week. this gives a great view on the amount of work performed by the openssh project after the fork of the last open source version. [1] https://www.openssh.com/history.html https://www.openssh.com/history.html
- fsckboy 4y agohttps://en.wikipedia.org/wiki/Ship_of_Theseus https://en.wikipedia.org/wiki/Ship_of_Theseus
- nayden 4y agothanks for bringing this to our attention. fixed now: https://github.com/bob-beck/foundation-web/commit/d34479b48abf65732ca5923f37d58e03b4d182b4 https://github.com/bob-beck/foundation-web/commit/d34479b48a...
- saagarjha 4y agoThis happens to already exist on macOS as VM_FLAGS_PERMANENT when setting up the mapping.
- chasil 4y agoThe ROP-gadget stuff hasn't migrated to any other kernels that I have seen. As I understand it, previous ROP-gadget hardening included compiler modifications on system/function call return, trap sleds, and some other stuff that I don't remember. This is on top of the kernel and library relink at every boot (to really make ASLR more potent). These modifications include a verification that the jump is in the stack, and not at the tail of some function (and the other thing eludes my understanding). These are some OpenBSD references on ROP hardening: https://undeadly.org/cgi?action=article;sid=20170622065629 https://undeadly.org/cgi?action=article;sid=20170622065629 https://www.openbsd.org/papers/rop.pdf https://www.openbsd.org/papers/rop.pdf https://www.openbsd.org/papers/asiabsdcon2019-rop-paper.pdf https://www.openbsd.org/papers/asiabsdcon2019-rop-paper.pdf I think that the most notorious exploit of "Return-Oriented Programming" (ROP-gadget) flaws was Solarwinds; I understand that a ROP exploit sealed their fate. Maybe Windows is doing some of this in their kernel. "At this point, we noticed that Serv-U.dll and RhinoNET.dll both have ASLR support disabled, making them prime locations for ROP gadgets..." https://www.microsoft.com/security/blog/2021/09/02/a-deep-dive-into-the-solarwinds-serv-u-ssh-vulnerability/ https://www.microsoft.com/security/blog/2021/09/02/a-deep-di...
- saagarjha 4y agoThis is because the ROP gadget hardening OpenBSD does is generally considered to be mostly useless by other kernels, which are moving to hardware-enforced control flow integrity instead.
- hggh 4y agoToo bad they don't accept peer-to-peer electronic cash
- 7vUYjPAG2fnx7fd 4y ago> Bitcoin donation via BitPay: The OpenBSD Foundation can accept donations in BTC via BitPay
- groby_b 4y agoYeah, but ideally you should make a donation of lasting value.
- notaplumber1 4y agoThat's what BitPay handles. The OpenBSD Foundation doesn't hold onto any Bitcoin, it's immediately converted into USD.
- andirk 4y agoAlmost every donation and purchase I have made would have been far more lucrative to the recipient had they kept it in BTC. But yes, I understand this is salty HN.
- hggh 4y agoPeer-to-peer means there isn't a third party involved, and BTC stopped being electronic cash around 2014
- na85 4y agoAnd thus the failure of BSD-style licensing is thrown into sharp relief: Why are these projects that are used by many large and extraordinarily profitable tech enterprises dependent on community donations? I recommend not donating, because to do so directly supports corporate parasitism.
- Sunspark 4y agoThe flip side of course is that improvements also come at the pace of volunteerism, and there are no boardroom meetings where a manager tells the BSD developers that they didn't type enough lines of code that week. If a corp wants a feature improved or implemented if it doesn't exist, they will have to pay someone and then they have to decide whether they will contribute it. If they do not, then they have to maintain a fork themselves which requires ongoing resources. At the end of the day, I don't think it really matters that much. The corps are providing a service not a software application. If they weren't using BSD, they'd be using something else.
- deleted 4y ago[deleted]
- iE4mHBzmoYezwbx 4y agoReally? Their biggest donors are large and extraordinarily profitable tech enterprises. (Like Google, Microsoft, and Facebook) And thus the success of BSD-style licensing is thrown into sharp relief. (Also the fact that you or I can go use it as much as we want for free and do whatever we want to it.)
- chasil 4y agoThere used to be complaint from OpenBSD that large corporate users of OpenSSH weren't donating anything, so I sent them $100. Those days appear to be over. https://www.theregister.com/2015/07/08/microsoft_donates_to_openbsd_foundation/ https://www.theregister.com/2015/07/08/microsoft_donates_to_...
- mekster 4y agoBetter than nothing but it's far from what the title describes as "rains cash". MS : $25k - $50k Google , FB : $10k - $25k For them, that's like saying "Hi". For the financial value the OpenBSD foundation is creating, that's a miniscule return.
- hansendc 4y agoThere honestly isn't that much "tech" to speak of here. We were literally talking about "immutable" mappings last week in Linux land: https://lore.kernel.org/all/b4f0dca5-1d15-67f7-4600-9a0a91e9d0bd@intel.com/ https://lore.kernel.org/all/b4f0dca5-1d15-67f7-4600-9a0a91e9... That said, this would be great to see in OpenBSD (or any other OS).
- alberth 4y agoThis is beyond my knowledge but is this akin to macOS binary/memory protection for the base system OS?
- geraldcombs 4y agoAs a more general question, is there a resource available that shows which memory protection schemes are available on various OSes? It'd be nice to see what the state of the art is on Linux, macOS, the BSDs, etc. in one place.
- pram 4y agoSeems like the second blurb is similar to the Page Protection Layer+Pointer Authentication Codes in XNU.
- saagarjha 4y agoNot really, PPL protects page tables and PAC provides CFI.
- landr0id 4y agoDifferent. These are enhanced mitigations to detect when a program is calling into the kernel from a weird state that should never happen in a well-formed program. It basically prevents certain types of exploits from successfully calling into the kernel. *the new mitigation just makes user-mode memory completely immutable. You can never "upgrade" a page's permissions or change its contents after it's been marked as immutable.
- deleted 4y ago[deleted]
- staticassertion 4y agoI was just discussing this sort of thing with some colleagues. Because the stack frame for main contains a bunch of other stuff - environment variables, cli args, etc - it makes it unreliable to try to instrument Linux systems and collect that information. A process can change its name, args, env, at any time. That sort of information is really helpful for forensics. Currently your only option is to pull data directly from kernel structures, which is fine, but most people aren't doing that. And then of course there's other cool stuff like being able to 'lock' system calls to the system provided libc, which openbsd can do since they already only support their provided libc. Unfortunately none of this is likely to get to Linux at any point because: a) I bet some insane userland processes fuck with their stacks b) Linux doesn't mandate any libc edit: Seems like there's some "what is this" being asked. Here's my loose understand! For starters, libc is the interface to the kernel. Very few programs make syscalls directly (except go programs i guess? lol) on Linux, but on openbsd it's just flat out not allowed. OpenBSD doesn't have the "GNU/Linux" dichotomy - it's all one package deal. As such, they get to mandate how userland calls into the kernel. Of course, you don't have to listen to openbsd today, because you can just... make those system calls directly. Easy. And this is relevant for security because attackers will do something called ROP, which effectively "reuses" bits of your already-executable code to issue system calls (you can google "return to libc" or "ret2libc"). So, first thing's first, have the kernel actually ensure that the sycall is issued from the memory that libc is mapped into. Cool, solved sort of. But what if the attacker overwrites that libc? Now you've verified that the call is coming from libc but you don't have integrity. With immutability the kernel will now enforce that system calls come from libc and that the code can't be overwritten. Of course, this can extend beyond libc, but I'm assuming that's the main point. This would presumably be a general system call that programs can use themselves to do all sorts of fun things. edit: Can't respond to replies, HN rate limited me :) sorry. Sounds like I need to read up a bit more, this doesn't address the use case I'd had in mind sadly, but still very cool nonetheless.
- jart 4y ago> Linux doesn't mandate any libc Neither does OpenBSD. You're misunderstanding how msyscall() works. It's like Highlander. There can be only one.
- teknopurge 4y agoI'm not adding insight to this thread, but I love the OpenBSD project. Theo and the team are goat engineers and industry advocates.
- jart 4y agoNow all we need is for PROT_EXEC to not imply PROT_READ like Android.
- brynet 4y agoThere was some work done on XOM (eXecute-only-memory) for arm64, but on at least x86 there isn't a separate page table bit for just read permissions, so there's no way[0][1] to express R^X, PROT_EXEC without PROT_READ is not possible. Amusingly the 80286 supported execute-only segments, but this was dropped from 32-bit x86. [0] It is possible on Intel in VM guests using EPT (Extended Page Tables), mlarkin@ experimented with protecting the host kernel in a special VM, called "Underjack". AMD SVM supports nothing like this. [1] The custom AMD APU SoC in Sony's PS5 console supports "xotext" via NDA'd extensions, but there's no public documentation. (If _anyone_ knows details, pls share) ... btw, PROT_WRITE-only mappings are also impossible on x86 as well, so PROT_WRITE implicitly means PROT_READ. Not that I'm aware of any valid reason anyone might want this.
- hansendc 4y ago> there's no way[0][1] to express R^X, PROT_EXEC without PROT_READ is not possible. I'll also add a [2]: [2] There's no way to do it in the page tables. But, if you have Protection Keys for Userspace (PKU), you can get it ... kinda. You can have a PROT_READ|PROT_EXEC mapping, assign it a pkey, then set PKEY_DISABLE_ACCESS in the PKRU register for that key. In fact, if you have a PKU CPU and you do an unadorned mmap(PROT_EXEC), the kernel will allocate you a pkey and do this under the covers FOR you. Anyone who can execute WRPKRU can easily undo this protection, but it's better than nothing.
- brynet 4y agokinda indeed. As far as I can tell Intel PKU was only on Server-CPUs/Xeons until at least the 11th Gen (only later models?), and AMD Zen 3. OpenBSD doesn't support protection keys, in any case.
- saagarjha 4y agoThis breaks PAN on ARM due to various unfortunate choices in the spec.
- roopy 4y agoWhat exploit technique is this mitigating?
- dang 4y agoUrl changed from https://undeadly.org/cgi?action=article;sid=20220902100648 https://undeadly.org/cgi?action=article;sid=20220902100648, which points to this.
- rwmj 4y agoI'm curious why Theo used a new syscall. Wouldn't it be sufficient to add a new MAP_IMMUTABLE flag to mmap which would "fix" the given range of pages' mappings and protections permanently? Can't call it MAP_FIXED sadly :-)
- akira2501 4y agommap explicitly is allowed to create new maps in place of existing mappings by just freeing the underlying mapping, in fact that's one use for MAP_FIXED in safely create circularly mapped buffers. And using MAP_IMMUTABLE with MAP_ANONYMOUS wouldn't seemingly be possible. I would think mprotect() would work, though. Since the new call works more like minherit() under the hood, he decided to just duplicate that mechanism for this.