LWN: Comments on "MWR Labs: Assessing the Tux Strength" https://lwn.net/Articles/403662/ This is a special feed containing comments posted to the individual LWN article titled "MWR Labs: Assessing the Tux Strength". en-us Thu, 04 Sep 2025 19:45:59 +0000 Thu, 04 Sep 2025 19:45:59 +0000 https://www.rssboard.org/rss-specification lwn@lwn.net Library randomization / prelink https://lwn.net/Articles/404416/ https://lwn.net/Articles/404416/ nix <div class="FormattedComment"> It's still higher than three bits. Not much higher though: there's simply not much room down there. ASCII-armouring was a nice idea, but I'm not sure how effective it is.<br> <p> </div> Fri, 10 Sep 2010 07:57:05 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/404328/ https://lwn.net/Articles/404328/ bronson <div class="FormattedComment"> It should be, yes. But it isn't.<br> <p> Good luck addressing it! People have tried and failed. I hear it's like sending ten thousand similar emails in an attempt to push a wall of jello.<br> </div> Thu, 09 Sep 2010 18:33:16 +0000 Debian mostly fails where Gentoo succeeds. https://lwn.net/Articles/404220/ https://lwn.net/Articles/404220/ blueness <div class="FormattedComment"> I'm currently maintaining Gentoo's hardened-sources. Ask away.<br> </div> Thu, 09 Sep 2010 13:17:54 +0000 Library randomization / prelink https://lwn.net/Articles/404109/ https://lwn.net/Articles/404109/ kbad <div class="FormattedComment"> From the pax dev (gentoo-hardened list):<br> <p> "a note here: fedora uses exec-shield which maps libraries in two different<br> regions: ascii-armor (lower 16MB) and the rest. i think what paxtest measured there is the former where the usable entropy is necessarily less than elsewhere and may not be representative of real life apps and their address spaces (not saying the whole ascii-armor region is worth anything for security though ;)"<br> </div> Wed, 08 Sep 2010 19:58:24 +0000 Library randomization / prelink https://lwn.net/Articles/404069/ https://lwn.net/Articles/404069/ gmaxwell <div class="FormattedComment"> Anyone know how the library randomization is being counted? 3 bits for fedora doesn't sound right. Is the 3 bits the value for a system vs itself or for this system vs all other systems?<br> <p> </div> Wed, 08 Sep 2010 18:26:32 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403883/ https://lwn.net/Articles/403883/ SEJeff <div class="FormattedComment"> Fodder for spender and perhaps jspaleta:<br> <a href="http://www.outflux.net/blog/archives/2010/09/07/cross-distro-default-security-protection-review">http://www.outflux.net/blog/archives/2010/09/07/cross-dis...</a><br> <p> It show Kees Cook's frustration with trying to get proactive security into Debian proper where they have already been in **buntu for several releases already.<br> </div> Tue, 07 Sep 2010 21:01:42 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403876/ https://lwn.net/Articles/403876/ jspaleta <div class="FormattedComment"> So no discussion about the value/trade-offs of prelink when PIE is not in use. That's unfortunate.<br> <p> -jef<br> </div> Tue, 07 Sep 2010 20:35:23 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403835/ https://lwn.net/Articles/403835/ kees <div class="FormattedComment"> See the thread for yourself. Here is why Debian rejected a global compiler change:<br> <p> <a href="http://www.mail-archive.com/debian-devel@lists.debian.org/msg277751.html">http://www.mail-archive.com/debian-devel@lists.debian.org...</a><br> </div> Tue, 07 Sep 2010 17:15:44 +0000 Add Mandriva? https://lwn.net/Articles/403804/ https://lwn.net/Articles/403804/ buchanmilne <div class="FormattedComment"> I know it is more effort to test on more distributions, but many other popular distros people might request are re-spins of one of the distros that have been tested.<br> <p> However, Mandriva is not a re-spin of any of the distros tested, and has enabled some of these features, and is also used as a base for a few other distros.<br> </div> Tue, 07 Sep 2010 14:08:05 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403786/ https://lwn.net/Articles/403786/ PaXTeam <div class="FormattedComment"> <font class="QuotedText">&gt; Of course newer distributions have the newer linux-2.6 features.</font><br> <p> 1. nothing prevents a distro from backporting features (and they often do), especially simple ones like ASLR.<br> <p> 2. not all tested features depend on the kernel.<br> </div> Tue, 07 Sep 2010 12:16:25 +0000 Bias : gentoo hardened vs standard kernel https://lwn.net/Articles/403777/ https://lwn.net/Articles/403777/ rahulsundaram <div class="FormattedComment"> No. Neither Red Hat nor SUSE have alternative kernels with more security features. Either it is in the default kernel or not. <br> </div> Tue, 07 Sep 2010 11:12:56 +0000 Bias : gentoo hardened vs standard kernel https://lwn.net/Articles/403776/ https://lwn.net/Articles/403776/ Alterego <div class="FormattedComment"> The study compares hardened version of gentoo with standard kernel.<br> <p> It would have been insteresting to compare with Debian grsecurity2 kernel (and i guess RedHat and SuSe also have hardened version)<br> <p> <p> </div> Tue, 07 Sep 2010 10:48:00 +0000 Debian mostly fails where Gentoo succeeds. https://lwn.net/Articles/403775/ https://lwn.net/Articles/403775/ Alterego <div class="FormattedComment"> We just need to take a gento hardened-kernel and put it in Debian.<br> <p> I hope the sync between several distro (to use 2.6.32 kernel) will help to fix this, and avoid duplicate (or useless) efforts from the various maintainers.<br> <p> Afaik Greg KH is one gentoo kernel maintainer, maybe this can explain several things ?<br> </div> Tue, 07 Sep 2010 10:26:20 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403765/ https://lwn.net/Articles/403765/ federico2 <div class="FormattedComment"> <font class="QuotedText">&gt; evaluating the latest stable for each distro seems fair to me.</font><br> <p> At the same time we should keep in mind that they have been released in different times and with different processes. Otherwise such comparison may be misleading.<br> <p> Debian puts a lot of efforts into releasing a distribution that contains only mature software, "old by design" so to speak, where many vulnerabilities have already been found and patched.<br> <p> The main reasons to do that are security and reliability.<br> <p> Other distributions (including Ubuntu) are releasing much newer software, mainly to provide a better desktop experience, so they can ship new security features.<br> <p> OTOH, all the cutting-edge software included inevitably contains many new vulnerabilities.<br> <p> In terms of trade-offs, given that the memory protection tools mitigate a specific set of vulnerabilities only, having mature software gives much more security in my opinion.<br> <p> <p> <p> <p> </div> Tue, 07 Sep 2010 09:25:54 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403767/ https://lwn.net/Articles/403767/ maks <div class="FormattedComment"> It is only fair if the compared distros have the same release cycle. So comparing Ubuntu with Fedora is just fine, they release every 6 month. Other wise the time of the experiement is just arbitrary and will effectively disfavor distributions with longer release cycles that don't shipp newer linux-2.6.<br> <p> They for example didn't test Red Hat or CentOS.<br> </div> Tue, 07 Sep 2010 09:22:02 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403757/ https://lwn.net/Articles/403757/ Klavs <div class="FormattedComment"> evaluating the latest stable for each distro seems fair to me. There will most likely never be a time where distro releases are in sync :)<br> </div> Tue, 07 Sep 2010 07:09:49 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403717/ https://lwn.net/Articles/403717/ hmh <div class="FormattedComment"> It is a bit better, but nowhere close to something you'd write home about.<br> </div> Mon, 06 Sep 2010 21:42:54 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403712/ https://lwn.net/Articles/403712/ maks <div class="FormattedComment"> Comparing apples with pears.<br> <p> Of course newer distributions have the newer linux-2.6 features. If they'd compared distributions that were released on the same date it be more interesting.<br> </div> Mon, 06 Sep 2010 21:18:27 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403693/ https://lwn.net/Articles/403693/ patrick_g <div class="FormattedComment"> The Debian version which was assessed is Lenny (5.0.4).<br> Perhaps the security level is better with Debian Squeeze (6.0) ?<br> </div> Mon, 06 Sep 2010 19:05:13 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403691/ https://lwn.net/Articles/403691/ rahulsundaram <div class="FormattedComment"> That would be a organizational failure to address. It should be possible to make technical changes consistently across package boundaries especially when it brings obvious benefits like security improvements.<br> </div> Mon, 06 Sep 2010 18:50:06 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403690/ https://lwn.net/Articles/403690/ foom <div class="FormattedComment"> It seems to me that it's fairly difficult for Debian as an organization to manage to make global settings changes like for those features.<br> </div> Mon, 06 Sep 2010 18:37:37 +0000 MWR Labs: Assessing the Tux Strength https://lwn.net/Articles/403686/ https://lwn.net/Articles/403686/ Adi <div class="FormattedComment"> It's said to see that Debian has lost in virtually all tests.<br> Quite an uneasy conclusion for distro so often used on servers.<br> </div> Mon, 06 Sep 2010 17:50:26 +0000