Linked by Eugenia Loli on Sat 12th Aug 2006 19:07 UTC
Permalink for comment 151885
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
News
Linked by Thom Holwerda on 05/25/13 0:45 UTC
Linked by Thom Holwerda on 05/24/13 23:59 UTC
Linked by Thom Holwerda on 05/24/13 22:33 UTC
Linked by Howard Fosdick on 05/24/13 21:41 UTC
Linked by Thom Holwerda on 05/24/13 14:44 UTC
Linked by Thom Holwerda on 05/23/13 23:22 UTC
Linked by Thom Holwerda on 05/23/13 22:04 UTC
Linked by Thom Holwerda on 05/23/13 22:01 UTC
Linked by Thom Holwerda on 05/23/13 17:52 UTC
Linked by Thom Holwerda on 05/22/13 22:23 UTC
More News »
Sponsored Links



Member since:
2006-05-29
that's also included in openbsd (and they're the first to implement it on the base system as far as free unix-like os is concern e.g. propolice, nx bit), yes there may be pax or any other protections patches in linux but the question is "is it included in the base?", the big answer is NO. if you want security, it must be from the base, from the ground up. (anyway i agree w/ you, fedora did a very good job in securing their distro). but other thing openbsd have that "might" not have on other major linux distros are the following:
W^X, .rodata segment, guard pages, randomized malloc()and mmap()
atexit() and stdio protection
privilege separation of common services "by default" (e.g. syslogd, dhcpd, tcpdump)
strlcpy() and strlcat()
chroot jailing of common services "by default" (e.g. httpd, bind)
and the constant code auditing (w/c i think linux does not have)