Reading over at this great privacy nerd and developer's site:
Micah Lee's Blog
https://micahflee.com/2016/01/debian-grsecurity/I learned that finally grsecurity seems to be going mainstream in Debian (haven't checked how Devuan, it's no-systemd fork, my favorite-to-be, stands on this, but I'm sure they'll catch up). Here:
https://wiki.debian.org/grsecurityand the packages:
https://packages.debian.org/search?suit ... inux-grsecAnyway, grsecurity seems to be going mainstream. Finally! If only NSA Linux went into history, and stay in the past from a point that we would live soon in the future... The point when it becomes obsolete. NSA, ahem, SELinux.
And that we remember the light that still shines about how it was introduced, way back to years of this interview that tells the story how the
LSM was invented for the sake of the rootkit hooks for the NSA, ahem, SELinux, ahem, hardening....
...[seems to be going mainstream] indeed. I'll give a title to this conversation btwn people that lead in Linux kernel (of which "Greg" in the conversation must be the signer of the stable Linux kernel, IIUC, Greg Kroah-Hartman)...
...[I'll give a title to this conversation] by copying one line from the conversation verbatim:
Who wants to see grsec fail?
https://soylentnews.org/comments.pl?sid ... ommentwrapI had long ago written that even Gentoo without grsec will become just nice looking crap. Even Gentoo, which is probably the most nerdy of all distros...!
Here, in bottom of this post in this topic:
NSA SELinux Support??? wrote:...
If Grsecurity were not viable in Gentoo, Gentoo will become just nice looking crap, nothing else.
---
And I'm glad to see that the industry is finally, it appears to me so, slowly catching up with what spender and PaX Team have long advocated needs to be done to fix the kernel.
And that there will probably be no more need for me to add much to this topic in the future... (But you never know about future, so lets wait and see...)
---
Miroslav Rovis
Zagreb, Croatia
http://www.CroatiaFidelis.hrTry refute:
rootkit hooks in kernel,
linux capabilities for intrusion? (Linus?)