Article 4J5K9 Cook: package hardening asymptote

Cook: package hardening asymptote

by
jake
from LWN.net on (#4J5K9)
On his blog, Kees Cook looks at some graphs of package hardening efforts in Ubuntu and Debian, noting that they have nearly completely flattened out over the last few years. He wonders what might be the next hardening feature on the horizon and speculates some on that: "What new compiler feature adoption could be measured? I think there are still a few good candidates"How about enabling -fstack-clash-protection (only in GCC, Clang still hasn't implemented it).Or how about getting serious and using forward-edge Control Flow Integrity? (Clang has -fsanitize=cfi for general purpose function prototype based enforcement, and GCC has the more limited -fvtable-verify for C++ objects.)Where is backward-edge CFI? (Is everyone waiting for CET?)"
External Content
Source RSS or Atom Feed
Feed Location http://lwn.net/headlines/rss
Feed Title LWN.net
Feed Link https://lwn.net/
Reply 0 comments