Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.lang.c > #43232

Re: The portability sacred cow

Message-ID <flvf2b-brj.ln1@wilbur.25thandClement.com> (permalink)
From <william@wilbur.25thandClement.com>
Subject Re: The portability sacred cow
Newsgroups comp.lang.c
References <lj1db3$ieu$1@speranza.aioe.org> <lj3b04$v80$1@dont-email.me>
Date 2014-04-21 10:04 -0700

Show all headers | View raw


David Brown <david.brown@hesbynett.no> wrote:
> On 20/04/14 23:14, jacob navia wrote:
> 
>> For instance, OpenBSD has a function free() that is security conscious
>> and erases the freed memory before reuse. This would have stopped the
>> heartbleed bug in OpenSSL but it wasn't used.
> 
> That has no serious connection with the heartbleed bug.
> 
> (I am not disagreeing that making their own malloc/free is a bad idea, 
> and I agree with you that obsessive portability is not good.)
> 
> First, if OpenBSD's free() would have been better than standard free() 
> or OpenSSL's free(), then it would only have helped the Heartbleed bug 
> on OpenBSD - not on the most commonly used platform (Linux).

OpenBSD's mitigation measures have resulted in the silent remediation of
many such bugs in open source applications.

For example, when OpenBSD recently switched to a 64-bit time_t, many open
source applications broke. The ones which were caught were fixed in the
ports tree and patches submitted upstream.

(FWIW, I believe NetBSD beat OpenBSD to switching to a 64-bit time_t. The
same process would have happened in their ports tree, as well.)

> Secondly, the problem was that the bug let an attacker read blocks of 
> memory - while some of these areas might have been free'd, and therefore 
> cleared if they had used OpenBSD's free(), lots of the rest of the space 
> could still have been in use and still contain data.

OpenBSD has the ability to place a guard page after an allocated block, and
to align sub-page-sized allocations so that even a one-byte read overflow
hits the guard page and segfaults the application.

But to catch the heartbleed bug someone would have needed to fuzz the
protocol, and I'm unsure if anybody was doing that.

Back to comp.lang.c | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-20 23:14 +0200
  Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-20 23:34 +0200
    Re: The portability sacred cow Geoff <geoff@invalid.invalid> - 2014-04-20 21:20 -0700
      Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-21 04:35 +0000
      Re: The portability sacred cow Kaz Kylheku <kaz@kylheku.com> - 2014-04-21 05:10 +0000
        Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-21 05:31 +0000
        Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-20 23:50 -0700
  Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-20 23:39 +0200
  Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-20 23:37 -0700
    Re: The portability sacred cow Ian Collins <ian-news@hotmail.com> - 2014-04-21 20:25 +1200
  Re: The portability sacred cow glen herrmannsfeldt <gah@ugcs.caltech.edu> - 2014-04-21 07:10 +0000
  Re: The portability sacred cow Ian Collins <ian-news@hotmail.com> - 2014-04-21 20:32 +1200
  Re: The portability sacred cow David Brown <david.brown@hesbynett.no> - 2014-04-21 16:46 +0200
    Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-21 10:04 -0700
      Re: The portability sacred cow David Brown <david.brown@hesbynett.no> - 2014-04-21 21:02 +0200
  Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-22 02:52 -0700
    Re: The portability sacred cow Ian Collins <ian-news@hotmail.com> - 2014-04-22 23:18 +1200
      Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-22 11:49 +0000
    Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-22 14:48 +0200
    Re: The portability sacred cow Richard <rgrdev_@gmail.com> - 2014-04-22 14:58 +0100
      Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-22 07:37 -0700
    Re: The portability sacred cow luser droog <luser.droog@gmail.com> - 2014-04-22 21:52 -0700
  Re: The portability sacred cow Johannes Bauer <dfnsonfsduifb@gmx.de> - 2014-04-22 16:58 +0200
    Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-22 17:24 +0200
      Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-22 17:25 +0200
    Re: The portability sacred cow Gareth Owen <gwowen@gmail.com> - 2014-04-22 19:11 +0100
  Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-22 21:59 +0200
    Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-22 14:02 -0700
      Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-23 01:04 +0200
        Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-22 17:52 -0700
          Re: The portability sacred cow <william@wilbur.25thandClement.com> - 2014-04-22 19:15 -0700
      Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-23 01:10 +0200
      Re: The portability sacred cow Thomas Jahns <jahns@idontlikespam.dkrz.de> - 2014-04-23 09:53 +0200
        Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-25 02:21 +0000
          Re: The portability sacred cow JohnF <john@please.see.sig.for.email.com> - 2014-04-25 06:36 +0000
            Re: The portability sacred cow Richard <rgrdev_@gmail.com> - 2014-04-25 14:02 +0200
            Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-25 18:17 +0000
              Re: The portability sacred cow Kaz Kylheku <kaz@kylheku.com> - 2014-04-25 18:27 +0000
                Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-25 21:57 -0700
                Re: The portability sacred cow Stephen Sprunk <stephen@sprunk.org> - 2014-04-26 00:02 -0500
                Re: The portability sacred cow Richard <rgrdev_@gmail.com> - 2014-04-26 11:35 +0200
                Re: The portability sacred cow JohnF <john@please.see.sig.for.email.com> - 2014-04-26 06:04 +0000
              Re: The portability sacred cow jacob navia <jacob@spamsink.net> - 2014-04-25 23:08 +0200
                Re: The portability sacred cow glen herrmannsfeldt <gah@ugcs.caltech.edu> - 2014-04-25 21:52 +0000
          Re: The portability sacred cow Thomas Jahns <jahns@idontlikespam.dkrz.de> - 2014-04-25 11:27 +0200
            Re: The portability sacred cow Richard <rgrdev_@gmail.com> - 2014-04-25 14:03 +0200
              Re: The portability sacred cow gazelle@shell.xmission.com (Kenny McCormack) - 2014-04-25 18:18 +0000
              Re: The portability sacred cow "Bill Cunningham" <nospam@nspam.invalid> - 2014-04-26 20:04 -0400
            Re: The portability sacred cow Malcolm McLean <malcolm.mclean5@btinternet.com> - 2014-04-25 06:05 -0700
              Re: The portability sacred cow Thomas Jahns <jahns@idontlikespam.dkrz.de> - 2014-04-25 17:43 +0200
                Re: The portability sacred cow Keith Thompson <kst-u@mib.org> - 2014-04-25 10:48 -0700

csiph-web