public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: Tom Wijsman <TomWij@gentoo.org>
To: gentoo-dev@lists.gentoo.org
Cc: ago@gentoo.org, toolchain@gentoo.org
Subject: Re: [gentoo-dev] Improve the security of the default profile
Date: Thu, 5 Sep 2013 12:47:01 +0200	[thread overview]
Message-ID: <20130905124701.2ce1b44d@TOMWIJ-GENTOO> (raw)
In-Reply-To: <2258190.ks74ypJstN@devil>

[-- Attachment #1: Type: text/plain, Size: 1158 bytes --]

On Thu, 05 Sep 2013 12:13:28 +0200
Agostino Sarubbo <ago@gentoo.org> wrote:

> Hello,
> 
> during an irc debate, me and other people just noticed that the
> default profile could use more flags to enhance the security.
> 
> An hint is here:
> https://wiki.ubuntu.com/ToolChain/CompilerFlags
> 
> Please argue about what we _don't_ use.
> 
> Note: please CC me in your response.

What I wonder about here is at which cost this does come, when looking
at the fstack-protector then I see that it "emits extra code"; so, now
the question is what kind of overhead this causes.

I am pretty sure security might not be that important on a real time
system that perhaps isn't connected to the internet; so, besides making
it the default, we might want to introduce the necessary means to turn
it off again, by the very least perhaps documentation would suffice.

Do you intend to discuss that flag or more generally any security flag?

-- 
With kind regards,

Tom Wijsman (TomWij)
Gentoo Developer

E-mail address  : TomWij@gentoo.org
GPG Public Key  : 6D34E57D
GPG Fingerprint : C165 AF18 AB4C 400B C3D2  ABF0 95B2 1FCD 6D34 E57D

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 490 bytes --]

  reply	other threads:[~2013-09-05 10:47 UTC|newest]

Thread overview: 45+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-09-05 10:13 [gentoo-dev] Improve the security of the default profile Agostino Sarubbo
2013-09-05 10:47 ` Tom Wijsman [this message]
2013-09-05 10:54   ` Agostino Sarubbo
2013-09-05 11:09     ` Tom Wijsman
2013-09-05 11:58       ` Agostino Sarubbo
2013-09-05 13:33       ` Rich Freeman
2013-09-05 10:54   ` Sergey Popov
2013-09-05 11:06 ` [gentoo-dev] " Mike Frysinger
2013-09-07  3:48   ` Rick "Zero_Chaos" Farina
2013-09-07  6:36     ` Parker Schmitt
2013-09-05 12:09 ` [gentoo-dev] " Ciaran McCreesh
2013-09-05 12:38   ` Tom Wijsman
2013-09-07 18:24   ` [gentoo-dev] " Martin Vaeth
2013-09-07 17:25 ` Ryan Hill
2013-09-07 18:10   ` Martin Vaeth
     [not found]     ` < 20130907151110.13ebc8a2@caribou.gateway.2wire.net>
2013-09-07 18:37     ` Rich Freeman
2013-09-07 18:50       ` Pacho Ramos
2013-09-07 19:52         ` Martin Vaeth
2013-09-07 21:11     ` Ryan Hill
2013-09-07 23:08       ` Rick "Zero_Chaos" Farina
2013-09-07 23:12         ` Rich Freeman
2013-09-08 14:12           ` Hinnerk van Bruinehsen
2013-09-09  0:06         ` Ryan Hill
2013-09-09 12:11           ` Martin Vaeth
2013-09-09 12:21           ` Rich Freeman
2013-09-10  3:00             ` Ryan Hill
2013-09-10  3:46               ` Peter Stuge
2013-09-11 22:04               ` Magnus Granberg
2013-09-10 17:50           ` Jeroen Roovers
2013-09-10 22:41           ` Richard Yao
2013-09-11  1:17             ` Rich Freeman
2013-09-12 15:03               ` Richard Yao
2013-09-12 15:12                 ` Richard Yao
2013-09-11  6:07             ` Ryan Hill
2013-09-11 18:23               ` Magnus Granberg
2013-09-12 15:07               ` Richard Yao
     [not found]           ` <522FA01E.4070602 @gentoo.org>
     [not found]             ` <CAGfcS_=VwAT0xYAny9hfd3tpRM61dt39Zcm7p0N8_pLzeyw1FQ@mail. gmail.com>
2013-09-11  4:49               ` Duncan
2013-09-11  6:49                 ` Ryan Hill
2013-09-11 18:48                 ` Magnus Granberg
2013-09-08 11:05       ` Martin Vaeth
2013-09-09  3:24         ` Ryan Hill
2013-09-08 11:24       ` Martin Vaeth
2013-09-12 15:23       ` Anthony G. Basile
2013-09-13  6:08         ` Ryan Hill
2013-09-07 19:50   ` Rick "Zero_Chaos" Farina

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20130905124701.2ce1b44d@TOMWIJ-GENTOO \
    --to=tomwij@gentoo.org \
    --cc=ago@gentoo.org \
    --cc=gentoo-dev@lists.gentoo.org \
    --cc=toolchain@gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox