Quotes of the week
Quotes of the week
Posted Jun 3, 2010 19:26 UTC (Thu) by spender (guest, #23067)In reply to: Quotes of the week by viro
Parent article: Quotes of the week
I didn't see any list of references for 3), you admit it's less frequent -- I'd say much less frequent/scarce.
Tossing around "security theatre" and "BDSM fetishism" as descriptors for the feature is unhelpful, especially when your criticism is only that it makes unnecessary checks and doesn't protect against a severe specific brokenness you can't provide examples of (unlike the case it does protect against, which you agree there's a "looong list of exploits" for).
Might I remind you of mmap_min_addr, which is a workaround for a specific case of a larger class of vulnerabilities? That didn't stop the developers from committing it. And unlike your example, I can point to plenty of OOPs reports showing exploitable uses of poisoned pointers, direct userland access in vgaarb, the vmsplice vuln on amd64, etc, that mmap_min_addr would have been helpless against.
If you can come up with something that covers 3) as well, more power to you, but I don't see how (and don't think you can reasonably justify how) it not covering something it wasn't meant to (that you can't provide even a handful of examples of) means it falls under "security theatre."
If you want to talk about actual security theatre going on in the kernel, we can have a completely different discussion about that.
-Brad
