KASLR: An Exercise in Cargo Cult Security (grsecurity blog)
[Posted March 27, 2013 by jake]
Over at the grsecurity blog, Brad Spengler and the PaX Team have co-written a
lengthy look at kernel address space layout randomization (KASLR) and its failures. "
KASLR is an easy to understand metaphor. Even non-technical users can make sense of the concept of a moving target being harder to attack. But in this obsession with an acronym outside of any context and consideration of its limitations, we lose sight of the fact that this moving target only moves once and is pretty easy to spot. We forget that the appeal of ASLR was in its cost/benefit ratio, not because of its high benefit, but because of its low cost."
(
Log in to post comments)