Tuesday, January 26. 2016

50-100% sounds very unreasonable even for super sensitive application. Why not go with grsecurity and hardened kernel?
#1 Anton on 2016-01-28 08:22 (Reply)
grsecurity and asan aren't really comparable, they target very different issues. grsecurity is an exploit mitigation tool to prevent kernel vulns (and it's amazing in this regard), asan targets userspace applications.

But I'm unsure myself if using this for production makes any sense. What I think is undoubtful is that it's a good testing ground.

If you're looking for something in userspace that's more practical then some of the more interesting efforts are the CFI and Safe Stack options of llvm:
#1.1 Hanno (Homepage) on 2016-01-28 13:40 (Reply)
By grsecurity I meant PaX. It does prevent userspace 0days.
Just run app-admin/paxtest to see all test cases.

IMHO, Address Sanitizer should be used by developers, PaX by end users.
#2 Anton on 2016-01-29 12:05 (Reply)
It warns about using ASan in production for security protection.
#3 kcwu on 2016-02-18 08:38 (Reply)
I've seen it. I will add a note to the text.
#3.1 Hanno (Homepage) on 2016-02-18 11:08 (Reply)

