-
Notifications
You must be signed in to change notification settings - Fork 1
Description
And so I think this is the place to let people know about it.
It's complex to explain. I have had at least these issues:
minipli/linux-unofficial_grsec#17
minipli/linux-unofficial_grsec#18
minipli/linux-unofficial_grsec#19
minipli/linux-unofficial_grsec#20
minipli/linux-unofficial_grsec#23
on one particular system, that could be due to bugs there, or could be due to attack.
I'm posting here about it because what I couldn't get with grsecunoff, I'm getting with dappersec: long hours and days without any issues like the above.
The complexity stands in that those issues could have been due to some Amd64 PSP feature(s) abused by attacker... Who knows?
OTOH, I perfectly understand how meltdown and spectre fixes are necessary. But to be missing features that this fork of grsec offers, by opting for upstream kernel, where there are no protection that this fork of grsec offers, I think that is even worse.
I have run 4.9.92 dappersec (available at: https://www.croatiafidelis.hr/gnu/deb/linux-4.9.92-dappersec180601-06/ )
and now 4.9.105 dappersec.