Re: state of security hardening build flag efforts

Here is where philosophy matters.  Yes, bindnow and pie can cause problems or slowdowns in certain (fortunately rare) cases.  Now, even though that is possible, that fact should not have any relevance on the choices for the defaults: on noticing that the flags have caused a problem, they can simply be disabled.  

For xorg, -pie,-bindnow certainly makes sense, but for the vast majority of other packages +all would be a far better default.

Best wishes,

