Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 12 Sep 2013 10:03:12 -1000
From:      Jonathon Wright <jonathon.s.wright@gmail.com>
To:        Brett Glass <brett@lariat.org>
Cc:        "freebsd-security@freebsd.org" <freebsd-security@freebsd.org>, John-Mark Gurney <jmg@funkthat.com>, Julian Elischer <julian@freebsd.org>
Subject:   Re: FreeBSD Transient Memory problem?
Message-ID:  <CAGX1DMbatuv25hsQYiO=mbpR4bZJCivQW3zvmNeTBAQd0LC4pA@mail.gmail.com>
In-Reply-To: <201309121953.NAA24598@mail.lariat.net>
References:  <CAGX1DMbQP=TggYQm-3hra0Od3gjgz5xQ8bEMMrueuhL6kuZMUA@mail.gmail.com> <20130912053559.GF68682@funkthat.com> <979901F9-5F25-4DF1-95A8-32473C55B25F@gmail.com> <52320144.2090807@freebsd.org> <CAGX1DMYAheUAV_eB4Z4R_YaMDx_LzrepEag5KyBC=EOxzhUiMQ@mail.gmail.com> <201309121953.NAA24598@mail.lariat.net>

next in thread | previous in thread | raw e-mail | index | archive | help
Great translation Brett, the whole team is rolling!

Unfortunately, its probably true. Yeah, I went to the site, interesting,
but I'm not sure how shady they are or not.
In either case, my problem still remains. I'm looking into what John-Mark
Gurney posted to me, it looks a bit promising as far as being able to
"demonstrate" the zeroing of the memory allocated prior to use.

For example, when I did a man malloc, the Z option states exactly that:
The problem though is it also states that "this is intended for debugging
and will impact performance negatively". That means I'm in between a rock
and hard spot:

1. If I turn it on, I'll have horrible performance. (I suppose I need a
/etc/malloc.conf example if I did if you have one)
2. if I don't turn it on, I am not able to address their so called 'issue'.




On Thu, Sep 12, 2013 at 9:53 AM, Brett Glass <brett@lariat.org> wrote:

> At 01:33 PM 9/12/2013, Jonathon Wright wrote:
>
>  *Description of Finding:* Object reuse cannot be verified. The FreeBSD
>>
>> servers used have not been evaluated or certified by NIAP. As such, it
>> cannot be verified that the operating system ensures transient memory
>> cleansing (object reuse) features are in place.
>>
>
> Translation: The FreeBSD Project doesn't participate in, and hasn't paid
> money to be certified by, a program run by the NSA... a shadowy government
> agency which has been known to actively compromise security and spy on
> citizens. We recommend that our clients move to a less secure OS so that
> their
> systems can be spied upon and their security compromised.
>
> --Brett Glass
>
> P.S. -- For more on NIAP, see www.niap-ccevs.org. Note that this site will
> deposit multiple tracking cookies in your browser which you may want to
> delete after visiting it.
>
>



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAGX1DMbatuv25hsQYiO=mbpR4bZJCivQW3zvmNeTBAQd0LC4pA>