On Thu, 1 Jul 2010 08:46:11 +0100 Radoslaw Madej <radeg...@o2.pl> wrote:
> Hi guys, > > I convinced the company I work for to allow me to spend some time on > reviewing different security aspects of Linux OS and different distros. As it > also involves Gentoo Hardened (which I also happily use on a daily basis), I > thought I'd share. :) > > http://labs.mwrinfosecurity.com/projectdetail.php?project=13&view=news > > There should be more to come in a near future. Any feedback appreciated :) > > Thanks to all hardened-dev for making the Hardened Gentoo happen! :) > Regards, > Radek Madej > A very good paper my friend, I enjoyed reading it :) I think you go into enough detail to keep even the less interested people reading and I hope that you manage to propagate this article (Maybe we could put a reference to it in the hardened docs?) so that more people become aware. Sure, some people are probably going to start question your testing methods and such because, like you mention in the paper, assessing security enabled on binaries can give false positives and negatives depending on how the code looks like. -- Mvh Daniel Kuehn