Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Kernel & Hardware
  • Search

Hardened sources - does it make sense without PaX

Kernel not recognizing your hardware? Problems with power management or PCMCIA? What hardware is compatible with Gentoo? See here. (Only for kernels supported by Gentoo.)
Post Reply
Advanced search
6 posts • Page 1 of 1
Author
Message
Uzytkownik
Guru
Guru
Posts: 399
Joined: Sun Oct 31, 2004 8:08 pm
Location: Bay Area, US
Contact:
Contact Uzytkownik
Website

Hardened sources - does it make sense without PaX

  • Quote

Post by Uzytkownik » Wed Jan 11, 2017 7:25 pm

I tried to run hardened Gentoo but I discovered that PaX is breaking too much. Are there any benefits to hardened sources w/out PaX?
I've probably left my head... somwhere. Please wait untill I find it.
Top
eccerr0r
Watchman
Watchman
Posts: 10239
Joined: Thu Jul 01, 2004 6:51 pm
Location: almost Mile High in the USA
Contact:
Contact eccerr0r
Website

  • Quote

Post by eccerr0r » Wed Jan 11, 2017 11:44 pm

Security is always a tradeoff for convenience.

If you're willing to sacrifice security (PaX) to get convenience (less breakage) then sure...

To quantify the security loss, it all depends on the person hacking your machine...
Intel Core i7 2700K/Radeon Firepro W2100/24GB DDR3/800GB SSD
What am I supposed watching?
Top
Uzytkownik
Guru
Guru
Posts: 399
Joined: Sun Oct 31, 2004 8:08 pm
Location: Bay Area, US
Contact:
Contact Uzytkownik
Website

  • Quote

Post by Uzytkownik » Thu Jan 12, 2017 12:59 am

eccerr0r wrote:Security is always a tradeoff for convenience.

If you're willing to sacrifice security (PaX) to get convenience (less breakage) then sure...

To quantify the security loss, it all depends on the person hacking your machine...
Yeah sure. My question was rather if hardened sources - Pax == vanilla sources or there is some hardening even without PaX/Grsecurity enabled.
I've probably left my head... somwhere. Please wait untill I find it.
Top
eccerr0r
Watchman
Watchman
Posts: 10239
Joined: Thu Jul 01, 2004 6:51 pm
Location: almost Mile High in the USA
Contact:
Contact eccerr0r
Website

  • Quote

Post by eccerr0r » Thu Jan 12, 2017 1:11 am

A lot of the security things are needed in conjunction with each other - removing one will weaken the remaining...

I view it as all or nothing.

Most of my machines I just run nothing and depend on correctness by design... Yeah...right... Convenience ended up winning out.
Intel Core i7 2700K/Radeon Firepro W2100/24GB DDR3/800GB SSD
What am I supposed watching?
Top
Uzytkownik
Guru
Guru
Posts: 399
Joined: Sun Oct 31, 2004 8:08 pm
Location: Bay Area, US
Contact:
Contact Uzytkownik
Website

  • Quote

Post by Uzytkownik » Thu Jan 12, 2017 1:19 am

eccerr0r wrote:A lot of the security things are needed in conjunction with each other - removing one will weaken the remaining...

I view it as all or nothing.
I think there are at least some shadows of grey between running military grade SELinux installation and ignoring error about self-signed certificate when you enter bank website... Security is obviously not all-or-nothing but need to be balanced against usability.
eccerr0r wrote:Most of my machines I just run nothing and depend on correctness by design... Yeah...right... Convenience ended up winning out.
I think you are answering not the question I am asking I am afraid. In my threat model I deem hardening as nice to have but not strictly necessary. I would like to just know if hardened sources contain any improvement other then PaX itself.
I've probably left my head... somwhere. Please wait untill I find it.
Top
Hu
Administrator
Administrator
Posts: 24386
Joined: Tue Mar 06, 2007 5:38 am

  • Quote

Post by Hu » Thu Jan 12, 2017 2:30 am

That depends on exactly what you disable at build time and/or runtime, but generally, yes, grsecurity includes a large number of security-related changes, not all of which require PaX enabled in order for them to function. Your other option is to describe some of the breaks that PaX is causing. Despite not being part of the upstream kernel, PaX is fairly widely used, so it is likely that other users have encountered any problems it causes and may be able to help you.
Top
Post Reply

6 posts • Page 1 of 1

Return to “Kernel & Hardware”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic