public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
From: Alan McKinnon <alan.mckinnon@gmail.com>
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] Re: Fwd:How about the gentoo server or cluster in production environment?
Date: Thu, 20 Feb 2014 22:59:59 +0200	[thread overview]
Message-ID: <53066CCF.3060509@gmail.com> (raw)
In-Reply-To: <20140220204103.GA3381@vidovic.ultras.lan>

On 20/02/2014 22:41, Nicolas Sebrecht wrote:
> On Thu, Feb 20, 2014 at 08:52:07PM +0400, Andrew Savchenko wrote:
> 
>> And this point is one of the highest security benefits in real world:
>> one have non-standard binaries, not available in the wild. Most
>> exploits will fail on such binaries even if vulnerability is still
>> there. 
> 
> While excluding few security issues by compiling less code is possible,
> believing that "non-standard binaries" (in the sense of "compiled for
> with local compilation flags") gives more security is a dangerous dream.
> 


+1

"non-standard binaries" is really just a special form of security by
obscurity. Or alternatively a special form of "no-one will eva figure
out my l33t skillz! Mwahahaha!"

Which is a very poor stance to take.

The total amount of code not compiled by setting some USE flags off is
on the whole not likely to be very much, and hoping with finger crossed
that the next weakness in a package will just happen to fall within a
code path that got left out by USE flags is a fools dream.

I'm glad you mentioned this Andrew, because the internets are full of
stupid advice like this "non-standard binary" nonsense. Yes, the
arguments at face value are difficult to refute with hard facts, but
those that do not known it is stupid are easily led into a sense of
false security, doesn't matter how many disclaimers are tagged on the end.

I reckon it's the duty of all knowledgeable sysadmins to stamp out this
crap HARD every time it raises it's head. To the user who brought it up
- this might seem overly harsh but I've yet to find a better method that
actually works and gets through to people.



-- 
Alan McKinnon
alan.mckinnon@gmail.com



  reply	other threads:[~2014-02-20 21:00 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <5297F0C8.3060403@gmail.com>
2014-02-19 23:40 ` [gentoo-user] Fwd: How about the gentoo server or cluster in production environment? Franklin Wang
2014-02-20  0:14   ` Nilesh Govindrajan
2014-02-20  0:36     ` Franklin Wang
2014-02-20  0:53       ` Facundo Curti
2014-02-20  1:06         ` Nilesh Govindrajan
2014-02-20  1:17         ` Franklin Wang
2014-02-20  9:28         ` thegeezer
2014-02-20 12:04         ` Tanstaafl
2014-02-20 12:24           ` Tanstaafl
2014-02-21  1:03           ` Facundo Curti
2014-02-21  1:39             ` Nilesh Govindrajan
2014-02-21 13:49             ` Tanstaafl
2014-02-27 13:09       ` Nick Cameo
2014-02-27 17:53         ` Facundo Curti
2014-03-21 13:37           ` Tom Wijsman
2014-02-20 10:29     ` [gentoo-user] Re: Fwd:How " Nicolas Sebrecht
2014-02-20 16:52       ` Andrew Savchenko
2014-02-20 20:41         ` Nicolas Sebrecht
2014-02-20 20:59           ` Alan McKinnon [this message]
2014-02-21 12:39             ` Andrew Savchenko
2014-02-26 11:44               ` Nicolas Sebrecht
2014-02-21 14:15             ` hasufell
2014-02-22  8:28               ` Alan McKinnon
2014-02-26 15:02                 ` hasufell
2014-02-26 10:55               ` Nicolas Sebrecht
2014-02-26 14:05                 ` Poison BL.
2014-02-26 15:03                 ` hasufell
2014-02-26 15:26                   ` Nicolas Sebrecht
2014-02-27  1:05                     ` hasufell
2014-02-21 11:16           ` Andrew Savchenko
2014-02-26 10:51             ` Nicolas Sebrecht
2014-02-20 14:35   ` [gentoo-user] Fwd: How " Andrew Savchenko
2014-02-21  7:35     ` Franklin Wang
2014-02-20 18:41   ` Andreas K. Huettel
2014-02-21  7:40     ` Franklin Wang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=53066CCF.3060509@gmail.com \
    --to=alan.mckinnon@gmail.com \
    --cc=gentoo-user@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox