43
submitted 23 hours ago by JoeKrogan@lemmy.world to c/linux@lemmy.ml
top 4 comments
sorted by: hot top controversial new old
[-] scratchandgame@lemmy.ml 2 points 2 hours ago

Wow. Hope that they will do better than kspp

[-] andyburke@fedia.io 11 points 20 hours ago

Why would anyone want to run unmainlined security patches from a company?

This is how CrowdStrike happened.

This feels like security via business decision which is always the opposite of security. At least this would be open source now? 🤷‍♂️

[-] ChiefSinner@lemm.ee 3 points 7 hours ago* (last edited 7 hours ago)

GrSecurity adds so many layers of protections to the kernel. They are literally decades ahead of the vanilla Linux kernel in terms of security. With all of the hardened GrSec settings checked/configured correctly, it stops the majority of 0 ring exploits (at least when I was running it before they went full GPLv2).

PaX is an awesome part of GrSec. Mprotect stops any read and write and execute access to memory in both user and kernel lands (only rx or wx). Stuff like web browsers won't work unless you have a program to mark it in elf to not use pax. However, this kills a lot of exploits with that turned on by itself (though there are probably work arounds if you are developing exploits which the other features would hopefully catch). That's why people installed 3rd party unmainlined security patches, but that's just me maybe idk.

I hope this venture will be more fruitful than the copy paste code that people kept trying to push to the hardened Linux kernel project (despite the maintainers best intentions and countless efforts to stop that)

[-] wildbus8979@sh.itjust.works 5 points 22 hours ago

This is very good news, the closing of grsec has been a huge loss for Linux hardening.

this post was submitted on 31 Oct 2024
43 points (100.0% liked)

Linux

47946 readers
1805 users here now

From Wikipedia, the free encyclopedia

Linux is a family of open source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991 by Linus Torvalds. Linux is typically packaged in a Linux distribution (or distro for short).

Distributions include the Linux kernel and supporting system software and libraries, many of which are provided by the GNU Project. Many Linux distributions use the word "Linux" in their name, but the Free Software Foundation uses the name GNU/Linux to emphasize the importance of GNU software, causing some controversy.

Rules

Related Communities

Community icon by Alpár-Etele Méder, licensed under CC BY 3.0

founded 5 years ago
MODERATORS