Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #184937 > unrolled thread

Re: When did Debian decide to enable PIE by default?

Started by"Thomas Schmitt" <scdbackup@gmx.net>
First post2017-08-09 16:40 +0200
Last post2017-08-10 10:00 +0200
Articles 10 — 6 participants

Back to article view | Back to linux.debian.user

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  Re: When did Debian decide to enable PIE by default? "Thomas Schmitt" <scdbackup@gmx.net> - 2017-08-09 16:40 +0200
    Re: When did Debian decide to enable PIE by default? Gene Heskett <gheskett@shentel.net> - 2017-08-09 16:50 +0200
      Re: When did Debian decide to enable PIE by default? Dan Ritter <dsr@randomstring.org> - 2017-08-09 17:10 +0200
        Re: When did Debian decide to enable PIE by default? Pascal Hambourg <pascal@plouf.fr.eu.org> - 2017-08-09 20:00 +0200
      Re: When did Debian decide to enable PIE by default? Tony van der Hoff <lists@vanderhoff.org> - 2017-08-09 17:30 +0200
      Re: When did Debian decide to enable PIE by default? Gene Heskett <gheskett@shentel.net> - 2017-08-10 02:30 +0200
        Re: When did Debian decide to enable PIE by default? <tomas@tuxteam.de> - 2017-08-10 10:10 +0200
          Re: When did Debian decide to enable PIE by default? Pascal Hambourg <pascal@plouf.fr.eu.org> - 2017-08-12 13:20 +0200
            Re: When did Debian decide to enable PIE by default? <tomas@tuxteam.de> - 2017-08-12 16:10 +0200
    Re: When did Debian decide to enable PIE by default? <tomas@tuxteam.de> - 2017-08-10 10:00 +0200

#184937 — Re: When did Debian decide to enable PIE by default?

From"Thomas Schmitt" <scdbackup@gmx.net>
Date2017-08-09 16:40 +0200
SubjectRe: When did Debian decide to enable PIE by default?
Message-ID<ucAjo-bt-9@gated-at.bofh.it>
Hi,

慕 冬亮 <mudongliangabcd@hotmail.com> wrote:
> When does Debian Team, or Security Team decide to enable PIE by default?

I guess it was one year ago. At least that's the dates one can see on
  https://wiki.debian.org/Hardening/PIEByDefaultTransition


Have a nice day :)

Thomas

[toc] | [next] | [standalone]


#184938

FromGene Heskett <gheskett@shentel.net>
Date2017-08-09 16:50 +0200
Message-ID<ucAt5-fu-37@gated-at.bofh.it>
In reply to#184937
On Wednesday 09 August 2017 10:31:48 Thomas Schmitt wrote:

> Hi,
>
> 慕 冬亮 <mudongliangabcd@hotmail.com> wrote:
> > When does Debian Team, or Security Team decide to enable PIE by
> > default?
>
> I guess it was one year ago. At least that's the dates one can see on
>   https://wiki.debian.org/Hardening/PIEByDefaultTransition
>
Interesting Thomas, but what the heck is PIE?  I know about PAE, but PIE?  
Whats it do?  Searching the above wiki returned only this thread.

Thanks, you too.
>
> Have a nice day :)
>
> Thomas


Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#184939

FromDan Ritter <dsr@randomstring.org>
Date2017-08-09 17:10 +0200
Message-ID<ucAMr-D4-43@gated-at.bofh.it>
In reply to#184938
On Wed, Aug 09, 2017 at 10:48:24AM -0400, Gene Heskett wrote:
> On Wednesday 09 August 2017 10:31:48 Thomas Schmitt wrote:
> 
> > Hi,
> >
> > 慕 冬亮 <mudongliangabcd@hotmail.com> wrote:
> > > When does Debian Team, or Security Team decide to enable PIE by
> > > default?
> >
> > I guess it was one year ago. At least that's the dates one can see on
> >   https://wiki.debian.org/Hardening/PIEByDefaultTransition
> >
> Interesting Thomas, but what the heck is PIE?  I know about PAE, but PIE?  
> Whats it do?  Searching the above wiki returned only this thread.
> 

https://en.wikipedia.org/wiki/Position-independent_code

It's a security measure.

-dsr-

[toc] | [prev] | [next] | [standalone]


#184948

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2017-08-09 20:00 +0200
Message-ID<ucDqW-243-23@gated-at.bofh.it>
In reply to#184939
Le 09/08/2017 à 17:05, Dan Ritter a écrit :
> On Wed, Aug 09, 2017 at 10:48:24AM -0400, Gene Heskett wrote:
>>
>> Interesting Thomas, but what the heck is PIE?

It is explained in the link posted by Thomas.

> It's a security measure.

No, PIE is not a security measure per se. It just allows to map an run 
the executable code anywhere in the address space instead of at a fixed 
location, which is useful for shared libraries for example. This feature 
is also used by Address Space Layout Randomization, which is a security 
measure.

[toc] | [prev] | [next] | [standalone]


#184940

FromTony van der Hoff <lists@vanderhoff.org>
Date2017-08-09 17:30 +0200
Message-ID<ucB5L-Jz-1@gated-at.bofh.it>
In reply to#184938
On 09/08/17 15:48, Gene Heskett wrote:
> Interesting Thomas, but what the heck is PIE?  I know about PAE, but PIE?  
> Whats it do?  Searching the above wiki returned only this thread.
>
> Thanks, you too.
>> Have a nice day :)
>>
>> Thomas
>
> Cheers, Gene Heskett

Position-independent executable:

https://en.wikipedia.org/wiki/Position-independent_code

[toc] | [prev] | [next] | [standalone]


#184961

FromGene Heskett <gheskett@shentel.net>
Date2017-08-10 02:30 +0200
Message-ID<ucJwl-6s8-3@gated-at.bofh.it>
In reply to#184938
On Wednesday 09 August 2017 10:52:26 慕 冬亮 wrote:

> On 08/09/2017 10:48 AM, Gene Heskett wrote:
> > On Wednesday 09 August 2017 10:31:48 Thomas Schmitt wrote:
> >> Hi,
> >>
> >> 慕 冬亮 <mudongliangabcd@hotmail.com> wrote:
> >>> When does Debian Team, or Security Team decide to enable PIE by
> >>> default?
> >>
> >> I guess it was one year ago. At least that's the dates one can see
> >> on https://wiki.debian.org/Hardening/PIEByDefaultTransition
> >
> > Interesting Thomas, but what the heck is PIE?  I know about PAE, but
> > PIE? Whats it do?  Searching the above wiki returned only this
> > thread.
>
> Please take a look at the following URL:
>
> https://wiki.debian.org/Hardening#DEB_BUILD_HARDENING_PIE_.28gcc.2Fg.2
>B-.2B-_-fPIE_-pie.29
>
Aha, another name for PIC, which I've only been writing code that uses it 
for 32 years. Also known as PCR, for Program Counter Relative.  Such 
code can be loaded into memory and executed without any patching.

> It is a security feature which combines with ASLR to do full address
> space randomization.
>
> > Thanks, you too.
> >
> >> Have a nice day :)
> >>
> >> Thomas
> >
> > Cheers, Gene Heskett


Cheers, Gene Heskett
-- 
"There are four boxes to be used in defense of liberty:
 soap, ballot, jury, and ammo. Please use in that order."
-Ed Howdershelt (Author)
Genes Web page <http://geneslinuxbox.net:6309/gene>

[toc] | [prev] | [next] | [standalone]


#184975

From<tomas@tuxteam.de>
Date2017-08-10 10:10 +0200
Message-ID<ucQHv-2LF-11@gated-at.bofh.it>
In reply to#184961
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Aug 09, 2017 at 08:22:58PM -0400, Gene Heskett wrote:
> On Wednesday 09 August 2017 10:52:26 慕 冬亮 wrote:
> 
> > On 08/09/2017 10:48 AM, Gene Heskett wrote:
> > > On Wednesday 09 August 2017 10:31:48 Thomas Schmitt wrote:
> > >> Hi,
> > >>
> > >> 慕 冬亮 <mudongliangabcd@hotmail.com> wrote:
> > >>> When does Debian Team, or Security Team decide to enable PIE by
> > >>> default?
> > >>
> > >> I guess it was one year ago. At least that's the dates one can see
> > >> on https://wiki.debian.org/Hardening/PIEByDefaultTransition
> > >
> > > Interesting Thomas, but what the heck is PIE?  I know about PAE, but
> > > PIE? Whats it do?  Searching the above wiki returned only this
> > > thread.
> >
> > Please take a look at the following URL:
> >
> > https://wiki.debian.org/Hardening#DEB_BUILD_HARDENING_PIE_.28gcc.2Fg.2
> >B-.2B-_-fPIE_-pie.29
> >
> Aha, another name for PIC, which I've only been writing code that uses it 
> for 32 years. Also known as PCR, for Program Counter Relative.  Such 
> code can be loaded into memory and executed without any patching.

Not exactly. PIC is "position independent code". Shared libraries have
been compiled like that for a long time since (especially under 32 bits)
you never knew where was a hole in memory to mmap the library in.

PIE is "position independent executable": it's about using PIC in the
Executable -- since that's the first to map in, the whole (well, nearly)
address space is available, and there's no need to generate PIC. Since
(under Intel) PIC is a tad slower than non-PIC, well...

But thanks PIE you can map the executable itself into a random address
(ASLR), which makes it more difficult for an attacker to find useful
"tools" in the executable image.

> > It is a security feature which combines with ASLR to do full address
> > space randomization.

Yes.

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmMEqkACgkQBcgs9XrR2kasngCeI49Xp+FPFo34Uy7FXvro2Vzq
+VMAn1QCl0A+qu/5PK9hua7Hp8q8ZJP7
=KyAN
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#185089

FromPascal Hambourg <pascal@plouf.fr.eu.org>
Date2017-08-12 13:20 +0200
Message-ID<udCCu-8pQ-13@gated-at.bofh.it>
In reply to#184975
Le 10/08/2017 à 10:00, tomas@tuxteam.de a écrit :
> 
> On Wed, Aug 09, 2017 at 08:22:58PM -0400, Gene Heskett wrote:
>>
>> Aha, another name for PIC, which I've only been writing code that uses it
>> for 32 years. Also known as PCR, for Program Counter Relative.  Such
>> code can be loaded into memory and executed without any patching.
> 
> Not exactly. PIC is "position independent code". Shared libraries have
> been compiled like that for a long time since (especially under 32 bits)
> you never knew where was a hole in memory to mmap the library in.
> 
> PIE is "position independent executable": it's about using PIC in the
> Executable

Sorry, but I fail to see the difference.
A shared library is executable, and the "code" in PIC is nothing but 
executable code, isn't it ?

[toc] | [prev] | [next] | [standalone]


#185094

From<tomas@tuxteam.de>
Date2017-08-12 16:10 +0200
Message-ID<udFgZ-1N3-7@gated-at.bofh.it>
In reply to#185089
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Sat, Aug 12, 2017 at 01:11:43PM +0200, Pascal Hambourg wrote:
> Le 10/08/2017 à 10:00, tomas@tuxteam.de a écrit :

[...]

> >PIE is "position independent executable": it's about using PIC in the
> >Executable
> 
> Sorry, but I fail to see the difference.
> A shared library is executable, and the "code" in PIC is nothing but
> executable code, isn't it ?

The difference is in intention (both are ELF these days). /bin/ls is
an "executable", /lib/x86_64-linux-gnu/libc.so.6 is a lib (yes, this
one has an entry point, you can invoke it from the command line).

While enabling PIC for libs has been done for a long time (IIRC the
first motivator was limited address space under 32 bit) and always
seemed a Good Idea(TM), for the executables I think it's ASLR what
brought a motivation with it. But I might be wrong.

Cheers
- -- tomás
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmPDAsACgkQBcgs9XrR2kbHewCdH//d0m1s14IIORFrqcGMs2DZ
KIwAn0TdaN6+D7uM5ce8EkMMcXvUj2Q6
=sZgI
-----END PGP SIGNATURE-----

[toc] | [prev] | [next] | [standalone]


#184974

From<tomas@tuxteam.de>
Date2017-08-10 10:00 +0200
Message-ID<ucQxP-2tn-1@gated-at.bofh.it>
In reply to#184937
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Aug 09, 2017 at 02:49:06PM +0000, 慕 冬亮 wrote:
> 
> 
> On 08/09/2017 10:31 AM, Thomas Schmitt wrote:
> > Hi,
> >
> > 慕 冬亮 <mudongliangabcd@hotmail.com> wrote:
> >> When does Debian Team, or Security Team decide to enable PIE by default?
> > I guess it was one year ago. At least that's the dates one can see on
> >    https://wiki.debian.org/Hardening/PIEByDefaultTransition
> Such a good news for me, a student learning information security. 
> However, I have a doubt, why does Debian enable PIE by default, other 
> than stack protector and FORTIFY_SOURCE that are already enabled by 
> default in the Ubuntu distribution?
> 
> I think stack protector(FORTIFY_SOURCE) has less overhead than PIE.

As far as I understand, stack protection and/or FORTIFY_SOURCE are
about protecting from buffer overflows. Stack protection sounds
pretty generic, in the case of FORTIFY_SOURCE, it's the compiler
doing extra compile-time checks (when possible) and inserting extra
run-time check code.

PIE isn't a security measure in itself -- it just allows such code
to be dynamically mapped at any address. But it enables address space
layout randomisation [1], which isn't a security measure in itself
either, but a *mitigation* technique: if an attacker has already
managed to take control of your program counter (e.g. by rewriting
a return address... possibly via a stack overflow, see above), you
make his/her life harder by not putting (potentially useful) code
at a place (s)he knows how to find.

It's like putting a chair in a dark room. Of course you should
try to make your door and lock as secure as possible. But just
in case...

>       No System Is Safe!

exactly :-)

Cheers
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlmMERMACgkQBcgs9XrR2kantACfXjHdLt0pWUu3sV6sui/8SB4F
J7UAnR0WzXmHw2WETK9UddYeHTjmc1u/
=MhEm
-----END PGP SIGNATURE-----

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web