[ubuntu-hardened] LTS Enablement Stacks; newer kernel (with new security features) and system security.

daniel curtis sidetripping at gmail.com
Thu Feb 23 10:21:08 UTC 2017


​Hi Casey and John

Thank You both for an answers. John, I think you're right by saying, that
"new features may introduce bugs but may also introduce new security
features​ (...)" Especially I'm interested in so called "copy to/from user
restrictions" feature. If it's about KASLR mechanism, I've read that it's
not such a good thing (see: 1.)

I know, that it's only opinion made by Mr Brad Spender, but it's very
interesting. Of course, I don't criticize the KASLR feature! I think it's
needed and so on. I just want to know as many as possible opinions on
various things etc. Nothing more, nothing less.

I think, that I will "need to evaluate risk/reward at an individual
kernel/feature level". Just as you've wrote, John. Anyway, thanks once
again for your opinions. It really helped me to understand all of this.

Thanks.

Best regards.
_____________
1. https://forums.grsecurity.net/viewtopic.php?f=7&t=3367
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ubuntu.com/archives/ubuntu-hardened/attachments/20170223/1df1e8b6/attachment.html>


More information about the ubuntu-hardened mailing list