On Tuesday, 22 November 2016 18:58:33 UTC, kev27  wrote:
> On Tuesday, November 22, 2016 at 8:57:56 PM UTC+2, kev27 wrote:
> > I saw this being retweeted by the Qubes account on Twitter. Can Grsec 
> > support still land in Qubes 4.0, or should we expect it for 4.1 or 4.2, etc?
> > 
> > I think if Grsec would be enabled by default in Qubes, it would be no 
> > question that Qubes is the most secure operating system out there.
> 
> Forgot to add the link:
> 
> https://twitter.com/coldhakca/status/801107979126784000

That's great news! Except PAX protections require more than just the kernel - 
they require PIE/PIC compiled binaries/SO's. There's also a number of security 
options that should be enabled in the GCC compiler (see the Gentoo hardened GCC 
profile). This means that the entire userspace would need to be recompiled and 
distributed as a hardened image - someone will need to do the legwork; and it 
will need to be signed by a trusted party.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/ef008e2c-4682-43c8-8118-e80435faba97%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to