Главная
Study mode:
on
1
Intro
2
OpenBSD?
3
Expectations
4
How do we measure exploit mitigations anyway?
5
Privilege separation and privilege drop
6
Example: rootless Xorg
7
Unveil
8
Hyperwhat?
9
Spectre v1, v2 and v3
10
AS(L)R
11
Position Independent Code/Executable
12
Libc/libcrypto symbols randomisation
13
Library order randomisation
14
Userland heap management
15
Rop gadgets removal, but why?
16
RETGUARD 2018
17
TCP SYN cookies
18
Development practices
19
Conclusion
Description:
Explore a systematic evaluation of OpenBSD's security mitigations in this 53-minute conference talk from the 36th Chaos Communication Congress (36C3). Delve into a comprehensive analysis of OpenBSD's advertised security features, examining their effectiveness, performance impacts, and potential vulnerabilities. Learn about various mitigations such as privilege separation, Unveil, ASLR, RETGUARD, and TCP SYN cookies. Gain insights into the rationale behind these security measures, their origins, and how they compare to implementations in other operating systems. Discover the importance of threat modeling and evidence-based security claims in operating system design. Evaluate OpenBSD's reputation as a secure operating system through a rational and systematic approach, considering factors like complexity, inspectability, and ease of bypass.

A Systematic Evaluation of OpenBSD's Mitigations

media.ccc.de
Add to list