Re: Non-random PIDs

From: Jason Dixon (jason_at_dixongroup.net)
Date: 08/01/04

  • Next message: Rik van Riel: "Re: Non-random PIDs"
    Date: Sun, 1 Aug 2004 17:36:36 -0400
    To: General Red Hat Linux discussion list <redhat-list@redhat.com>
    
    

    On Aug 1, 2004, at 5:32 PM, Rik van Riel wrote:

    > On Sun, 1 Aug 2004, Jason Dixon wrote:
    >
    >> I see that there is a maintained random-PID patch for the 2.4 series.
    >> The author claims it was rejected by Alan Cox because it was merely
    >> "security through obscurity". I'm a little surprised to hear that,
    >> but
    >> oh well.
    >
    > It is true, though. The random-PID patch might decrease
    > the chance of exploiting a certain bug by a small factor,
    > but that's no substitute for actually fixing the bug ...

    Obviously, fixing any bugs that could be exploited by this should be
    the priority by any responsible developer. Nevertheless, you have to
    ask yourself, what advantage is there to generating a pid as pid+1,
    rather than via entropy? If all things are equal, I would think that
    random PID generation is simply a better design.

    --
    Jason Dixon, RHCE
    DixonGroup Consulting
    http://www.dixongroup.net
    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: Rik van Riel: "Re: Non-random PIDs"

    Relevant Pages

    • Re: DEFCON 16 and Hacking OpenVMS
      ... You are correct in that what I did in exploiting the fact that INSTALL ... bug on VAX in which we took a different approach. ... on the bug we modified SYSUAF.DAT using a system service to enable all ... code on Alpha) to access $CREPRC. ...
      (comp.os.vms)
    • Re: Permanently disable mouse acceleration
      ... > like yourself takes it personally when I point out a bug in a software ... > system and then discuss various methods of fixing it. ... you don't even know how to write a basic flame. ... > something completely irrelavent to the problem. ...
      (comp.os.linux.setup)
    • [ANN]TCAD xp.a.1 released and 30% discount for merry Xmas
      ... add/remove point for TMyPolyline and TMyPolygon ... fixing Rule component bug ... fixing group/ungroup shapes order bug ... TCAD xp.a user can upgrade in free, please tell us the order no. ...
      (borland.public.delphi.thirdpartytools.general)
    • RE: [Full-Disclosure] Re: Full Disclosure != Exploit Release
      ... While I agree that they should be fixing their problems, ... >> wasn't important to fix. ... > specific bug. ... The information contained in this email and any attachments is ...
      (Full-Disclosure)
    • Re: A proposal; making 2.6.20 a bugfix only version.
      ... >>> cool stuff instead of fixing up any other issues we have. ... If we manage to get everyone focused on bug fixing only for the ... > entire cycle the backlog won't be growing. ... to work on the kernel, but when I do have time I try to fix bugs. ...
      (Linux-Kernel)