Conversation

This Tweet was deleted by the Tweet author. Learn more
Replying to and
HardenedBSD doesn't care about 32-bit arch's. The primary author of the paper had reached out to us during his research. He was very confused about how different ASLR implementations work. His testing methodology and algorithms weren't accurate. This research paper is flawed.
1
Replying to and
The paxtest application has the proper algorithms to measure ASLR entropy. Note that paxtest cannot properly measure ASR entropy. FreeBSD is implementing ASR. This, paxtest cannot measure and compare between fbsd and hbsd.
1
Replying to and
ASLR can be extended with finer-grained bases via userspace features, and paxtest is mostly oblivious to that. It is capable of seeing one extremely tiny aspect of the difference between malloc implementations based on the entropy of one allocation between different executions.
1
1
Replying to and
glibc: Heap randomization test (PIE): 32 quality bits (guessed) jemalloc: Heap randomization test (PIE): 23 quality bits (guessed) hardened_malloc: Heap randomization test (PIE): 41 quality bits (guessed) Entropy of a specific allocation is such a tiny aspect of it though.
1
1
Show replies