On Fri, Apr 17, 2020 at 02:58:06PM +0200, Marcin Wojtas wrote:
> Hi,
> 
> Together with our customers, Semihalf is interested in improving the status
> of security mitigations enablement in FreeBSD. To start with, based on our
> initial research it seems that after 2019 enhancements the ASLR/PIE
> features are in pretty much ready state.
> 
> Building the world using the 'WITH_PIE' flag produced proper binaries and
> the sanity showed no obvious degradations. Additionally, for the ASLR we
> performed a comparison of the pax tests (
> https://github.com/opntr/paxtest-freebsd) for amd64/arm64 and they indicate
> the feature is working fine after setting the according sysctl knobs. I'd
> be happy to present the results and discuss the details, but firstly I'd
> like to ask more general questions:

Quick note: paxtest's algorithms for measuring ASLR was meant to test
ASLR, not FreeBSD's ASR implementation. Thus, paxtest results for
FreeBSD's ASR are moot.

Link to the relevant discussion, as pointed out by the dude who coined
the term ASLR: https://reviews.freebsd.org/D5603#120017

Thanks,

-- 
Shawn Webb
Cofounder / Security Engineer
HardenedBSD

GPG Key ID:          0xFF2E67A277F8E1FA
GPG Key Fingerprint: D206 BB45 15E0 9C49 0CF9  3633 C85B 0AF8 AB23 0FB2
https://git-01.md.hardenedbsd.org/HardenedBSD/pubkeys/src/branch/master/Shawn_Webb/03A4CBEBB82EA5A67D9F3853FF2E67A277F8E1FA.pub.asc

Attachment: signature.asc
Description: PGP signature

Reply via email to