State of the Kernel Self Protection Project
State of the Kernel Self Protection Project
Posted Sep 1, 2016 3:21 UTC (Thu) by spender (guest, #23067)Parent article: State of the Kernel Self Protection Project
What isn't mentioned (because of the natural bias of the reporting on this site, to only regurgitate upstream kernel developer opinions) is that not one original useful security defense has come out of the KSPP contributors -- it's all ripoffs of grsecurity/PaX and some security theater thrown in (PS: look for yet another generic KASLR defeat this October). In some cases the ripoffs are entire copy+pastes of our work, done with no understanding whatsoever, and in multiple instances Intel's copyright slapped over the entire file without having made any modifications at all. Anything they can't figure out (like the full PAX_USERCOPY code, despite numerous attempts) gets punted on so they can rush out a KSPP success story and get those fancy cargo-culted buzzwords out into articles like this.
If KSPP is in need of a new slogan, I suggest: "KSPP: All the parts of grsecurity/PaX that are simple enough for us to copy+paste and take credit for"
-Brad
