Date: Thu, 12 Sep 2013 10:03:12 -1000 From: Jonathon Wright <jonathon.s.wright@gmail.com> To: Brett Glass <brett@lariat.org> Cc: "freebsd-security@freebsd.org" <freebsd-security@freebsd.org>, John-Mark Gurney <jmg@funkthat.com>, Julian Elischer <julian@freebsd.org> Subject: Re: FreeBSD Transient Memory problem? Message-ID: <CAGX1DMbatuv25hsQYiO=mbpR4bZJCivQW3zvmNeTBAQd0LC4pA@mail.gmail.com> In-Reply-To: <201309121953.NAA24598@mail.lariat.net> References: <CAGX1DMbQP=TggYQm-3hra0Od3gjgz5xQ8bEMMrueuhL6kuZMUA@mail.gmail.com> <20130912053559.GF68682@funkthat.com> <979901F9-5F25-4DF1-95A8-32473C55B25F@gmail.com> <52320144.2090807@freebsd.org> <CAGX1DMYAheUAV_eB4Z4R_YaMDx_LzrepEag5KyBC=EOxzhUiMQ@mail.gmail.com> <201309121953.NAA24598@mail.lariat.net>
next in thread | previous in thread | raw e-mail | index | archive | help
Great translation Brett, the whole team is rolling! Unfortunately, its probably true. Yeah, I went to the site, interesting, but I'm not sure how shady they are or not. In either case, my problem still remains. I'm looking into what John-Mark Gurney posted to me, it looks a bit promising as far as being able to "demonstrate" the zeroing of the memory allocated prior to use. For example, when I did a man malloc, the Z option states exactly that: The problem though is it also states that "this is intended for debugging and will impact performance negatively". That means I'm in between a rock and hard spot: 1. If I turn it on, I'll have horrible performance. (I suppose I need a /etc/malloc.conf example if I did if you have one) 2. if I don't turn it on, I am not able to address their so called 'issue'. On Thu, Sep 12, 2013 at 9:53 AM, Brett Glass <brett@lariat.org> wrote: > At 01:33 PM 9/12/2013, Jonathon Wright wrote: > > *Description of Finding:* Object reuse cannot be verified. The FreeBSD >> >> servers used have not been evaluated or certified by NIAP. As such, it >> cannot be verified that the operating system ensures transient memory >> cleansing (object reuse) features are in place. >> > > Translation: The FreeBSD Project doesn't participate in, and hasn't paid > money to be certified by, a program run by the NSA... a shadowy government > agency which has been known to actively compromise security and spy on > citizens. We recommend that our clients move to a less secure OS so that > their > systems can be spied upon and their security compromised. > > --Brett Glass > > P.S. -- For more on NIAP, see www.niap-ccevs.org. Note that this site will > deposit multiple tracking cookies in your browser which you may want to > delete after visiting it. > >
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAGX1DMbatuv25hsQYiO=mbpR4bZJCivQW3zvmNeTBAQd0LC4pA>