On Tuesday, 22 November 2016 18:58:33 UTC, kev27 wrote: > On Tuesday, November 22, 2016 at 8:57:56 PM UTC+2, kev27 wrote: > > I saw this being retweeted by the Qubes account on Twitter. Can Grsec > > support still land in Qubes 4.0, or should we expect it for 4.1 or 4.2, etc? > > > > I think if Grsec would be enabled by default in Qubes, it would be no > > question that Qubes is the most secure operating system out there. > > Forgot to add the link: > > https://twitter.com/coldhakca/status/801107979126784000
That's great news! Except PAX protections require more than just the kernel - they require PIE/PIC compiled binaries/SO's. There's also a number of security options that should be enabled in the GCC compiler (see the Gentoo hardened GCC profile). This means that the entire userspace would need to be recompiled and distributed as a hardened image - someone will need to do the legwork; and it will need to be signed by a trusted party. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/ef008e2c-4682-43c8-8118-e80435faba97%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
