@grsecurity is geblokkeerd
Weet je zeker dat je deze Tweets wilt bekijken? @grsecurity wordt niet gedeblokkeerd door Tweets te bekijken.
-
@halvarflake randomization is not the way today. Stop the attack at the origin (prevent the first non authorized return) -
@_pablosole_@ortegaalfredo BTW, you can't just blindly reorder the Linux kernel, some objects depend on specific order (e.g. initcalls) -
@marcan42 extrapolating some bogus theory out of a single data point = captain hindsight FUD -
Als antwoord op Hector Martin
@marcan42 and importantly *NOT* mentioning that the change was to code with an existing int truncation flaw that would cause the same DoS -
Als antwoord op Hector Martin
@marcan42 saying we don't have code review, that it's exploitable, that patches you don't have access to were affected -
Als antwoord op Hector Martin
@marcan42 Happy to take real criticism and bug reports, but what you've been sending out to your followers is simply FUD -
@_pablosole_@ortegaalfredo still not a ROP defense and I would never advertise it as one -
Als antwoord op Pablo Sole
@_pablosole_@ortegaalfredo I was doing this with the kernel years ago: -rw-r--r-- 1 spender spender 1172 Aug 13 2011 rand_ld.c -
Als antwoord op Hector Martin
@marcan42 the bug is 'really sad' yet your own analysis was wrong, I don't see you repeating that to your 21k clueless followers -
@marcan42 you're acting like a child who found his first bug and in being oh-so-proud of it is blowing it completely out of proportion -
Als antwoord op Hector Martin
@marcan42 Stop spreading FUD, I had changes queued up for both of them (two of the other patches I also applied to -test) -
New test patch up with improved protection against irrelevant infosec anklebiters
9 retweets 11 vind-ik-leuks -
@marcan42 also you failed to mention in your diatribe that the upstream code had an int truncation that also triggered SIZE_OVERFLOW -
@marcan42 The proper fix (aka not yours, Mr. High Horse Captain Obvious) will be in the next patch, but good luck obtaining it -
Als antwoord op Hector Martin
@marcan42 Done with your diatribe? Good, now read this: https://forums.grsecurity.net/viewtopic.php?t=4342&p=16222#p16224 … aka "try reading the code next time" -
Als antwoord op grumpy
@arnaud_fontaine yes, no changes there. 4.5 should be out soon -
#news Grsecurity is choosing 4.4 as its next stable kernel tree and will continue to support 3.14 through the end of 201719 retweets 29 vind-ik-leuks -
@lazytyped@BrandonPrry@daveaitel because people for whom bugfixing = security learn nothing by fixing yet another bug -
@lazytyped@BrandonPrry@daveaitel just for the curiosity of seeing how long they last and make the point that bugfixing != security -
Als antwoord op twiz
@lazytyped@BrandonPrry@daveaitel not true; I sit on a bunch, never use them, and care very much
@grsecurity heeft nog niet getweet.
Het laden lijkt wat langer te duren.
Twitter is mogelijk overbelast of het ondervindt een tijdelijke onderbreking. Probeer het opnieuw of bekijk de Twitter-status voor meer informatie.
Je bent misschien ook geïnteresseerd in
·- © 2016 Twitter
- Over
- Help
- Voorwaarden
- Privacy
- Cookies
- Advertentie-informatie
twiz
grsecurity