[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: goals for hardening Debian: ideas and help wanted



* Thorsten Glaser <tg@debian.org>, 2014-04-29, 15:35:
A wide misconception. Chroots are easily implemented and add security almost for free (often /dev/log is all that is needed) and so can be used by default without any potential problems, they also never bring new risks and always make life difficult for an attacker to raise priviledges or get what they are actually after when done correctly. Even at a simple level it should be obvious that they can just nullify the payload so the attacker simply goes elsewhere. Does

Bwahahahahahahahahahahahahahahahahahaha!

Do you also laugh at people who enable hardening complier flags?

Security is not black and white.

--
Jakub Wilk


Reply to: