From mboxrd@z Thu Jan 1 00:00:00 1970 From: Leo Famulari Subject: Re: Hardening (was: Re: tor: update to 0.2.9.9) Date: Tue, 24 Jan 2017 16:02:33 -0500 Message-ID: <20170124210233.GB30771@jasmine> References: <20170124111934.16080-1-contact.ng0@cryptolab.net> <20170124190726.GB6110@jasmine> <87bmuw2n3j.fsf@wasp.i-did-not-set--mail-host-address--so-tickle-me> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:46458) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cW8El-0002rO-Ia for guix-devel@gnu.org; Tue, 24 Jan 2017 16:02:44 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cW8Ec-0004Us-Dn for guix-devel@gnu.org; Tue, 24 Jan 2017 16:02:39 -0500 Received: from out1-smtp.messagingengine.com ([66.111.4.25]:47416) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cW8Ec-0004UF-AQ for guix-devel@gnu.org; Tue, 24 Jan 2017 16:02:34 -0500 Content-Disposition: inline In-Reply-To: <87bmuw2n3j.fsf@wasp.i-did-not-set--mail-host-address--so-tickle-me> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: ng0 Cc: guix-devel@gnu.org On Tue, Jan 24, 2017 at 08:56:48PM +0000, ng0 wrote: > Leo Famulari writes: > > Should we build Tor with "--enable-expensive-hardening"? > > I will take a look later what can be applied other than the > default configure flags. > > I'm all for hardening, but it seems that the first basic ideas > for Guix are stuck in the idea state. As far as I can tell, --enable-expensive-hardening is specific to Tor, so it's not relevant to the project of hardening all Guix packages. > It would be great to see some movement on this during this > year. I volunteer to help with it, though I don't have as much > experience with SELinux (and only basic experience with > GrSecurity without a modular kernel like GuixSD uses). Yes, this effort needs a champion.