The point is that the security of a grsecurity protected system depends on the userspace being compiled in a special way. The binaries need to be compiled with pie, and shared objects need to be compiled with pic. There are also some other mitigations like SSP.
A grsecurity kernel on it's own is not adequate enough. Someone will need to distribute a hardened userspace. The coldhaka kernel is in alpha. It's a start but not a solution. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/31fb0390-9210-423f-a5eb-f59f681fed15%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
