Very nice! Is there a blog post explaining the principles and ideals/goals grsec takes when building mitigations? Say, how do you avoid building "just" speed bumps? @spendergrsec @_minipli
Here's a short new blog from @_minipli on the results of our exploit review applied to a recently-described in-the-wild Android kernel exploit.
It shows how we use our compiler-based defenses to land security improvements for customers quickly:
grsecurity.net/constify_fast…
2
1
7
as always, you can start with the original PaX docs from over 2 decades ago, those principles still hold :).
Oct 5, 2023 · 5:33 AM UTC
1

