Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
| Message-ID | <flvf2b-brj.ln1@wilbur.25thandClement.com> (permalink) |
|---|---|
| From | <william@wilbur.25thandClement.com> |
| Subject | Re: The portability sacred cow |
| Newsgroups | comp.lang.c |
| References | <lj1db3$ieu$1@speranza.aioe.org> <lj3b04$v80$1@dont-email.me> |
| Date | 2014-04-21 10:04 -0700 |
David Brown <david.brown@hesbynett.no> wrote: > On 20/04/14 23:14, jacob navia wrote: > >> For instance, OpenBSD has a function free() that is security conscious >> and erases the freed memory before reuse. This would have stopped the >> heartbleed bug in OpenSSL but it wasn't used. > > That has no serious connection with the heartbleed bug. > > (I am not disagreeing that making their own malloc/free is a bad idea, > and I agree with you that obsessive portability is not good.) > > First, if OpenBSD's free() would have been better than standard free() > or OpenSSL's free(), then it would only have helped the Heartbleed bug > on OpenBSD - not on the most commonly used platform (Linux). OpenBSD's mitigation measures have resulted in the silent remediation of many such bugs in open source applications. For example, when OpenBSD recently switched to a 64-bit time_t, many open source applications broke. The ones which were caught were fixed in the ports tree and patches submitted upstream. (FWIW, I believe NetBSD beat OpenBSD to switching to a 64-bit time_t. The same process would have happened in their ports tree, as well.) > Secondly, the problem was that the bug let an attacker read blocks of > memory - while some of these areas might have been free'd, and therefore > cleared if they had used OpenBSD's free(), lots of the rest of the space > could still have been in use and still contain data. OpenBSD has the ability to place a guard page after an allocated block, and to align sub-page-sized allocations so that even a one-byte read overflow hits the guard page and segfaults the application. But to catch the heartbleed bug someone would have needed to fuzz the protocol, and I'm unsure if anybody was doing that.
Back to comp.lang.c | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-20 23:14 +0200
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-20 23:34 +0200
Re: The portability sacred cow Geoff <geoff@invalid.invalid> - 2014-04-20 21:20 -0700
Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-21 04:35 +0000
Re: The portability sacred cow Kaz Kylheku <kaz@kylheku.com> - 2014-04-21 05:10 +0000
Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-21 05:31 +0000
Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-20 23:50 -0700
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-20 23:39 +0200
Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-20 23:37 -0700
Re: The portability sacred cow Ian Collins <ian-news@hotmail.com> - 2014-04-21 20:25 +1200
Re: The portability sacred cow glen herrmannsfeldt <gah@ugcs.caltech.edu> - 2014-04-21 07:10 +0000
Re: The portability sacred cow Ian Collins <ian-news@hotmail.com> - 2014-04-21 20:32 +1200
Re: The portability sacred cow David Brown <david.brown@hesbynett.no> - 2014-04-21 16:46 +0200
Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-21 10:04 -0700
Re: The portability sacred cow David Brown <david.brown@hesbynett.no> - 2014-04-21 21:02 +0200
Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-22 02:52 -0700
Re: The portability sacred cow Ian Collins <ian-news@hotmail.com> - 2014-04-22 23:18 +1200
Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-22 11:49 +0000
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-22 14:48 +0200
Re: The portability sacred cow Richard <rgrdev_@gmail.com> - 2014-04-22 14:58 +0100
Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-22 07:37 -0700
Re: The portability sacred cow luser droog <luser.droog@gmail.com> - 2014-04-22 21:52 -0700
Re: The portability sacred cow Johannes Bauer <dfnsonfsduifb@gmx.de> - 2014-04-22 16:58 +0200
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-22 17:24 +0200
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-22 17:25 +0200
Re: The portability sacred cow Gareth Owen <gwowen@gmail.com> - 2014-04-22 19:11 +0100
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-22 21:59 +0200
Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-22 14:02 -0700
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-23 01:04 +0200
Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-22 17:52 -0700
Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-22 19:15 -0700
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-23 01:10 +0200
Re: The portability sacred cow Thomas Jahns <jahns@idontlikespam.dkrz.de> - 2014-04-23 09:53 +0200
Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-25 02:21 +0000
Re: The portability sacred cow JohnF <john@please.see.sig.for.email.com> - 2014-04-25 06:36 +0000
Re: The portability sacred cow Richard <rgrdev_@gmail.com> - 2014-04-25 14:02 +0200
Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-25 18:17 +0000
Re: The portability sacred cow Kaz Kylheku <kaz@kylheku.com> - 2014-04-25 18:27 +0000
Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-25 21:57 -0700
Re: The portability sacred cow Stephen Sprunk <stephen@sprunk.org> - 2014-04-26 00:02 -0500
Re: The portability sacred cow Richard <rgrdev_@gmail.com> - 2014-04-26 11:35 +0200
Re: The portability sacred cow JohnF <john@please.see.sig.for.email.com> - 2014-04-26 06:04 +0000
Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-25 23:08 +0200
Re: The portability sacred cow glen herrmannsfeldt <gah@ugcs.caltech.edu> - 2014-04-25 21:52 +0000
Re: The portability sacred cow Thomas Jahns <jahns@idontlikespam.dkrz.de> - 2014-04-25 11:27 +0200
Re: The portability sacred cow Richard <rgrdev_@gmail.com> - 2014-04-25 14:03 +0200
Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-25 18:18 +0000
Re: The portability sacred cow "Bill Cunningham" <nospam@nspam.invalid> - 2014-04-26 20:04 -0400
Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-25 06:05 -0700
Re: The portability sacred cow Thomas Jahns <jahns@idontlikespam.dkrz.de> - 2014-04-25 17:43 +0200
Re: The portability sacred cow Keith Thompson <kst-u@mib.org> - 2014-04-25 10:48 -0700
csiph-web