public inbox for gentoo-hardened@lists.gentoo.org
 help / color / mirror / Atom feed
From: Brian Kroth <bpkroth@gmail.com>
To: gentoo-hardened@lists.gentoo.org
Subject: Re: [gentoo-hardened] Grsecurity / PaX in danger!
Date: Mon, 19 Jan 2009 16:11:26 -0600	[thread overview]
Message-ID: <20090119221125.GB16609@gmail.com> (raw)
In-Reply-To: <6d6452241ca58bcb748d96be52484b52.squirrel@atoth.sote.hu>

My ability to keep up on these things comes and goes as I'm sure
everyone's does, so I just noticed this:
http://lwn.net/Articles/313621/#Comments

For those of us who clearly see the benefit of the PaX/Grsecurity
patchset, but don't have enough kernel programming knowledge to directly
contribute (I'm sure there are many of us out there), I'm curious, what
can we do to help ensure (even parts of) the project's survival, either
in or out of the mainline kernel?

Unfortunately I work for a state facing a major deficit, so sponsorship
by my "company" isn't really a possibility, though your idea of NSA
sponsorship intrigues me.  Has that, or some other form of grant, been
pursued?  

How much "sponsorship" would be required?

Would lobbying or other efforts to get certain features ready for
mainline kernel inclusion help or does that go against the
PaX/Grsecurity teams' wishes?

What would those features be?  Should users be polled for what they'd
like to see attempted first?

Is this even the right place to discuss such a proposal?  Probably other
distros like Debian would be interested in the project's survival as
well, however in my experience the gentoo-hardened list has generally
been more active than the grsecurity one.

For what it's worth I made my donation today.

Thanks again,
Brian

atoth@atoth.sote.hu <atoth@atoth.sote.hu> 2008-12-29 06:22:
> While Grsecurity 2.1.12 has been officially released, an alarming message
> has been also included in the announcement.
> http://www.grsecurity.net/news.php#grsec2112
> If no sponsors will be found in a few months, Grsecurity can be expected
> to become discontinued.
> 
> I encourage every individuals for a small donation (I've already done) and
> companies using the software to consider sponsoring Brad & PaxTeam.
> 
> I personally could donate $10 monthly for keeping the essential, crucial
> piece of patch alive. If every user could make a small donation the
> project could be saved by an effort of the community.
> 
> If I were the US cabinet, I would immediately instruct NSA to save
> Grsecurity & PaX.
> 
> Regards,
> Dw.
> -- 
> dr Tóth Attila, Radiológus, 06-20-825-8057, 06-30-5962-962
> Attila Toth MD, Radiologist, +36-20-825-8057, +36-30-5962-962



      reply	other threads:[~2009-01-19 22:11 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-12-29  5:22 [gentoo-hardened] Grsecurity / PaX in danger! atoth
2009-01-19 22:11 ` Brian Kroth [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20090119221125.GB16609@gmail.com \
    --to=bpkroth@gmail.com \
    --cc=gentoo-hardened@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox