Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751896AbdITLtX (ORCPT ); Wed, 20 Sep 2017 07:49:23 -0400 Received: from ou.quest-ce.net ([195.154.187.82]:47302 "EHLO ou.quest-ce.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751488AbdITLtV (ORCPT ); Wed, 20 Sep 2017 07:49:21 -0400 X-Greylist: delayed 1810 seconds by postgrey-1.27 at vger.kernel.org; Wed, 20 Sep 2017 07:49:21 EDT Message-ID: <1505906284.3490.5.camel@opteya.com> From: Yann Droneaud To: Solar Designer , riel@redhat.com Cc: linux-kernel@vger.kernel.org, danielmicay@gmail.com, tytso@mit.edu, keescook@chromium.org, hpa@zytor.com, luto@amacapital.net, mingo@kernel.org, x86@kernel.org, linux-arm-kernel@lists.infradead.org, catalin.marinas@arm.com, linux-sh@vger.kernel.org, ysato@users.sourceforge.jp, kernel-hardening@lists.openwall.com Date: Wed, 20 Sep 2017 13:18:04 +0200 In-Reply-To: <20170919171600.GA31441@openwall.com> References: <20170524155751.424-1-riel@redhat.com> <20170919171600.GA31441@openwall.com> Organization: OPTEYA Content-Type: text/plain; charset="UTF-8" X-Mailer: Evolution 3.24.5 (3.24.5-1.fc26) Mime-Version: 1.0 Content-Transfer-Encoding: 8bit X-SA-Exim-Connect-IP: 80.12.91.199 X-SA-Exim-Mail-From: ydroneaud@opteya.com Subject: Re: [kernel-hardening] [PATCH v2 0/5] stackprotector: ascii armor the stack canary X-SA-Exim-Version: 4.2.1 (built Mon, 26 Dec 2011 16:24:06 +0000) X-SA-Exim-Scanned: Yes (on ou.quest-ce.net) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 349 Lines: 17 Hi, Le mardi 19 septembre 2017 à 19:16 +0200, Solar Designer a écrit : > > We could put/require a NUL in the middle of the canary, > but with the full canary being only 64-bit at most that would also > make some attacks easier. > Are you suggesting to randomly select which byte to set to 0 in each canary ? Regards. -- Yann Droneaud OPTEYA