3 ms·
The issue is that it restricts from locking-down and securing the system with Write xor Execute memory. So it has system wide implication. https://en.wikipedia
by asdfsa32 1mo ago
The issue is that it restricts from locking-down and securing the system with Write xor Execute memory. So it has system wide implication.
https://en.wikipedia.org/wiki/W%5EX https://en.wikipedia.org/wiki/W%5EX
- PhilipRoman 1mo agoW^X is typically per mapping, not per memory page and does not interfere with JIT compilation.
- asdfsa32 1mo agoSure, but it still means that the OS has to decide who is allowed to do it and to what extent. Sophisticated worms like Stuxnet would be much harder with strict W^X for example, since CVE-2010-2568 and the like would be much harder to execute.
- orf 1mo ago> Sure, but it still means that the OS has to decide who is allowed to do it and to what extent It has to do that anyway?
- pjmlp 1mo agoSigned binaries with the proper assigned OS capabilities.
- asdfsa32 1mo agoYes, but with JIT, you can't really verify what the application does upfront. That is the entire point.
- deleted 1mo ago[deleted]
- pjmlp 1mo agoCapabilities are a way to control that, and the point being that only responsible proven applications get the certificate, hence how it all goes on iOS.
- asdfsa32 1mo agoYou're making the assumption that "responsible" is something provable, but that is not the case, it is specially not easy to prove software is secure from tampering its behaviour.
- pjmlp 1mo agoFor that there is bytecode verification as intermediate step, and if you want to go crazy with security, hardware memory tagging with capabilities. Which at this point most companies would rather save money and forbid JIT altogether. Note that mainframes and micros have JIT environments that aren't at the same safety level as regular desktop PCs. For example, https://medium.com/@dhemanthc/ibm-i-architecture-how-timi-and-slic-enable-hardware-independence-82aea3f2dae3 https://medium.com/@dhemanthc/ibm-i-architecture-how-timi-an...
- kllrnohj 1mo agoNonsense, there's no "system wide implications". Mappings are per process, and W^X is just a strategy to help harden individual processes, not the entire system. There's no herd immunity here. JITs do not grant the ability to bypass any OS/system sandboxes. The lack of W^X doesn't do that, either. If a process opts out of W^X, such as to enable a JIT, it's voluntarily making itself less hardened, but at the end of the day this isn't any more meaningful than the program being allowed to be written in, say, C, which also voluntarily reduces the processes security hardening.
- asdf88990 1mo agoYou don’t understand OP’s point because you’re assuming vulnerabilities don’t exist. That is utter nonsense.
- kllrnohj 1mo agoNo, you're not understanding mine. Nobody builds an OS/system expecting that every executable is perfectly well behaved with zero bugs and zero ill intent. Applications are allowed to run code. JITs just run code in that same process. They are already limited to what the process was already allowed to do in the first place. And my point about C is literally that even without a JIT, applications can still have arbitrary execution vulnerabilities. A JIT intended to run untrusted code as part of a sandbox, like a browser, is a big risk. But that's because of the untrusted code part, not the JIT. By comparison, something like a Python or Java JIT is as near as makes no difference completely risk free. The JIT is working on exclusively "trusted" code. Same basic concept applies here with this database usage.