{"id":379,"date":"2010-09-07T11:06:42","date_gmt":"2010-09-07T19:06:42","guid":{"rendered":"http:\/\/www.outflux.net\/blog\/?p=379"},"modified":"2010-09-07T12:45:28","modified_gmt":"2010-09-07T20:45:28","slug":"cross-distro-default-security-protection-review","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2010\/09\/07\/cross-distro-default-security-protection-review\/","title":{"rendered":"cross-distro default security protection review"},"content":{"rendered":"<p>The <a href=\"http:\/\/lwn.net\/Articles\/403662\/\">recent work<\/a> by MWR Labs does a reasonable job showing Debian&#8217;s poor pro-active security and why I am so <a href=\"http:\/\/www.mail-archive.com\/debian-devel@lists.debian.org\/msg277751.html\">frustrated<\/a> about it: we have not been able to move very quickly at getting it enabled. While my <a href=\"http:\/\/packages.qa.debian.org\/h\/hardening-wrapper.html\">hardening-includes<\/a> package is available to maintainers that want to turn on protections for their builds, it&#8217;s still a far cry from having it be distro-wide, and it doesn&#8217;t protect people that build stuff by hand. We were able to solve this in Ubuntu very directly a while ago by improving the compiler itself.<\/p>\n<p>Since SSP and FORTIFY_SOURCE can only be confirmed (it&#8217;s not possible without source analysis to see if it <em>should<\/em> have been enabled), it would be nice to see what binaries differed between distros on this. Most of the &#8220;SSP disabled&#8221; stuff are binaries that lack character arrays on the stack to begin with, and the FORTIFY_SOURCE stuff may have done all compile-time protections.  The comments about &#8220;other distributions could potentially enable it for a few more binaries&#8221; is a bit misleading since, for all but Debian, both SSP and FORTIFY_SOURCE <em>are<\/em> enabled for all builds.<\/p>\n<p>I did appreciate the nod to Ubuntu for being the only distro without by-default PIE that built Firefox with PIE. Given that Firefox is the #2 most vulnerable piece of software in a desktop distro, it was important to do it. (The #1 most vulnerable is the kernel itself &#8212; I&#8217;m counting number of fixed CVEs for this stat.)<\/p>\n<p>The kernel analysis by MWR seems rather incomplete. Also, it&#8217;s not clear to me which distros were running a PAE kernel, which would change some of the results. I didn&#8217;t see any mention of several other userspace protections that the kernel can provide, for example:<\/p>\n<ul>\n<li>symlink and hardlink protections (Gentoo Hardened and Ubuntu 10.10 only)<\/li>\n<li>PTRACE protections (Gentoo Hardened and Ubuntu 10.10 only)<\/li>\n<\/ul>\n<p>And a ton more that only Gentoo Hardened could boast, due to their use of grsecurity.<\/p>\n<p>I&#8217;d also be curious to see <em>performance<\/em> comparisons, too. They compared 4 general-purpose distros against a tuned-specifically-for-security-hardening distro, which seems a bit unfair. How about comparing against vanilla Gentoo instead? I can tell you who would be best then. :)<\/p>\n<p style='text-align:left'>&copy; 2010, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>The recent work by MWR Labs does a reasonable job showing Debian&#8217;s poor pro-active security and why I am so frustrated about it: we have not been able to move very quickly at getting it enabled. While my hardening-includes package is available to maintainers that want to turn on protections for their builds, it&#8217;s still [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,18,6,14,19],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/379"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=379"}],"version-history":[{"count":2,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/379\/revisions"}],"predecessor-version":[{"id":381,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/379\/revisions\/381"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=379"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=379"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=379"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}