Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 2 May 2012 08:33:04 -0400
From:      Richard Yao <ryao@cs.stonybrook.edu>
To:        Giorgos Keramidas <keramida@ceid.upatras.gr>
Cc:        Jerry McAllister <jerrymc@msu.edu>, freebsd-hackers@freebsd.org, Mehmet Erol Sanliturk <m.e.sanliturk@gmail.com>, Andy, Wojciech Puchar <wojtek@wojtek.tensor.gdynia.pl>, Young <ayoung@mosaicarchive.com>
Subject:   Re: Ways to promote FreeBSD?
Message-ID:  <4FA12980.6080101@cs.stonybrook.edu>
In-Reply-To: <CAKR2__3C2r1LTk3Sf0w52Jjp3KZhPduqrN0vsvr1VCCb%2BtF4UQ@mail.gmail.com>
References:  <CAHMRaQf=M0ULOH=KnqzOXvczSM0Lb6apCoQkJegqyU3e8%2BgShA@mail.gmail.com> <alpine.BSF.2.00.1204272025080.5846@wojtek.tensor.gdynia.pl> <20120427203117.GA2055@gizmo.acns.msu.edu> <CAOgwaMv_9c_W4fek-kGhQV3B5bKv4RnEFn_6ixn2LS7qDPma6Q@mail.gmail.com> <CAKR2__3C2r1LTk3Sf0w52Jjp3KZhPduqrN0vsvr1VCCb%2BtF4UQ@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help
--------------enigCD3CD4780B23C213F7499218
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

On 05/02/12 04:55, Giorgos Keramidas wrote:
> On Fri, Apr 27, 2012 at 11:18 PM, Mehmet Erol Sanliturk
> <m.e.sanliturk@gmail.com> wrote:
>> Another point is that server installers are highly educated with respe=
ct to
>> desktop installers and their numbers are small with respect to desktop=

>> users .
>>
>> For them , it is very easy to "harden" FreeBSD after installation if e=
ver
>> it is needed , because during installation , it is a simple question t=
o ask
>> :
>>
>> Will  this be used as a Server ?
>=20
> Judging from the amount of effort it takes to "harden" a system
> that already starts a thousand services (typical "desktop Linux"
> scenario these days), and the number of times I've seen this
> sort of customization cause even more headaches, I'd say this
> is a slightly exaggerated statement.

You might be thinking of SELinux, which is not the only option for
hardening. The Gentoo Hardened project offers multiple options for
hardening, of which SELinux is only one:

http://www.gentoo.org/proj/en/hardened/
http://www.gentoo.org/proj/en/hardened/primer.xml

The PaX/GrSecurity patchset for Linux provides strong ASLR to the both
the kernel and userland. To my knowledge, the only BSD that supports
ASLR is OpenBSD.

> You are right that a "plain user" does not care about why their
> CD-ROM is not accessible after installation, but there are two
> different ways to approach this:
>=20
> - Install and enable everything by default, hoping that nothing
>   bad happens when an unused service is exploitable.
> - Install a minimal system and build from there.
>=20
> Most Linux distributions pick the first option. _Some_ Linux
> distributions pick the second option (e.g. Gentoo).

You might be thinking of Gentoo Linux, rather than Gentoo. The term
Gentoo also covers Gentoo/FreeBSD and Gentoo Prefix. Gentoo/FreeBSD
replaces the Linux kernel and GNU userland with FreeBSD while Gentoo
Prefix provides a userland package manager to UNIX-compatible systems:

http://www.gentoo.org/proj/en/gentoo-alt/bsd/fbsd/index.xml
http://www.gentoo.org/proj/en/gentoo-alt/prefix/

Neither Gentoo/FreeBSD nor Gentoo Prefix are Linux distributions, so it
would be better to refer to Gentoo Linux when talking about the Gentoo
Linux distribution.

Also, Gentoo's minimalist design is not a form of hardening provided by
the Gentoo Hardened project. Most Gentoo Hardened users would not
consider it to be hardening.


--------------enigCD3CD4780B23C213F7499218
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.17 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/

iQIcBAEBAgAGBQJPoSmDAAoJELFAT5FmjZuEefUQALy9+3wNB0vzUeVHh4P9pWkc
Xr/Ff6Hci3EB4/tRgyVH8e+cchpBOrpltlAaknDjRtzigdQISAzJO/J/CzjPuowO
BfF+l+Nt7F40+YKolTLrXmlRCV2BZawxurCLMrEotoO10BFKxVb/r1GwrJjPt74p
WdosqbSQkoVvNgQ235SNVib0lwh2ZrnesUurzKqAuUZbh2fSXUIJO8f+VQkV6gGq
BX6ADJbCZIrpKkyo5MPs9y2sYTJaUXTHK5HLho4ZNajrQh9ued8sIwTH3mjriIs3
FhNURoFjQkahnHgiPEvirN+9l99XPaqhO9toSIRDsLeAKIXlRbT6SMli2cBWqRbP
E428hS0J9CPVcxhJKnxL+FTxnuADPEjGvNwsHLJrfBX6OpMN1RThEC56YAzAxHM+
9n2I171KblsLhpEajepkUW3FK5OBueLtCJ3i8EIzUPDF76HmOMHzYaX+Vg4X99ln
d58yu64RBTAA27jtEJSa+MeeL5Pt7gQTeU/FflkNdQCoKdF8fB5Q1+ui43Toqqtb
iAzVJcohbGFbu+EDuiaM7bNhQO5O3GqucQ0nXCF3SCizLrEh7iNvJt4gSSAP6zxu
sEWH/aCO67M1gosQCnmDfMYGA3L+758cFpAaVlhJW/jFP+fuVr44BZBDgfQ8IZSu
u9FN2a5VxVgpB0B6j7SQ
=eZpa
-----END PGP SIGNATURE-----

--------------enigCD3CD4780B23C213F7499218--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4FA12980.6080101>