Tarnkappe.info · @tarnkappeinfo
1529 followers · 3787 posts · Server social.tchncs.de
Shawn Webb · @lattera
1325 followers · 5171 posts · Server bsd.network

After testing, I've re-enabled on 13-CURRENT/amd64 now that at least some of the issues have been resolved due to the 8.0.0 import (we inherit the import from our upstream, ).

#retpoline #hardenedbsd #llvm #freebsd

Last updated 7 years ago

Aroop Roelofs :verified: · @finlaydag33k
954 followers · 10861 posts · Server social.linux.pizza

Well, the (yes, I use Windows... unfortunately...) patches for /#Spectre really do fuckover my PC heavily...

Ran some with them enabled then ran some benchmarks with them disabled...
The difference was 45%!!!???

Seriously, what the fuck... I though my PC was getting outdated af with how slow it is at times but it's just fucking me over again...
Let's hope in W10.1903 will do a better job at this...

#retpoline #microsoft #benchmarks #meltdown #windows

Last updated 7 years ago

Shawn Webb · @lattera
1325 followers · 5171 posts · Server bsd.network

enables support for in base: svnweb.freebsd.org/changeset/b

has had it enabled for a few months for amd64.

#freebsd #retpoline #hardenedbsd

Last updated 7 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

#retpoline #freebsd

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

The clang/llvm 6.0.0 patch landed in HEAD: svnweb.freebsd.org/base?view=r

It's nice to see it in FreeBSD. This landed in a couple weeks back.

Next, FreeBSD needs to switch to ld.lld as the default linker in order to actually make use of retpoline. Since HardenedBSD already switched to ld.lld, we're able to make full use of retpoline.

Importing the retpoline patch is a good first step.

#retpoline #freebsd #hardenedbsd

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

IBRS/IBPB support lands in HEAD: svnweb.freebsd.org/changeset/b

We'll make good use of this in , especially since we have applied to the entire ecosystem in 12-CURRENT/amd64.

#freebsd #hardenedbsd #retpoline #spectre #infosec

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

In the latest 12-CURRENT/amd64, is compiled with:

1. PIE
2. full RELRO
3. CFI (with the cfi-icall scheme disabled)
4. SafeStack
5.

If you're looking at deploying a relay or exit node, please consider deploying on HardenedBSD.

Using HardenedBSD will help keep you, the Tor network, and its users more secure. Let's piss off the bad guys together. :)

#hardenedbsd #tor #retpoline

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

The 12-CURRENT/amd64 package repo has been updated with applied to every package.

This makes HardenedBSD the first OS to apply retpoline to the entire operating system experience (world + kernel + packages).

#hardenedbsd #retpoline #freebsd #infosec #spectre

Last updated 8 years ago

WhilelM · @whilelm
616 followers · 8078 posts · Server mstdn.fr

GCC 7.3 released
lwn.net/Articles/745385/

7.3 is out. This is mainly a bug-fix release, but it does also contain the support needed to build the (and perhaps other code) with resistance to the variant-2 vulnerability.

#gcc #retpoline #kernel #spectre

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network
Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

Once the main patch lands in 12-CURRENT, I'll start on auditing the hand-written assembly in the kernel for indirect jumps and manually apply retpoline there, too.

#retpoline #hardenedbsd

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

Full disk encrypted APU3c4 fully ready to go mobile. My new mobile setup with with the PTI and patches applied.

#tor #hardenedbsd #retpoline

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

Going to migrate one of my APU2c4 devices over to the feature branch. This will be my first AMD system testing retpoline on HardenedBSD.

#retpoline #hardenedbsd

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

Migrated my work laptop over to the feature branch this morning. Everything went smoothly.

#retpoline #hardenedbsd

Last updated 8 years ago

newnix@exile.digital · @architect
3269 followers · 6535 posts · Server linuxrocks.online

Ok, simple tests reveal that rc runs fine with enabled, but apparently segfaults when compiled with enabled, not sure why that is at this point, also not sure when I'll be able to test it out more, but I'm back to using the best ${SHELL} available

#retpoline #cfi

Last updated 8 years ago

newnix@exile.digital · @architect
3269 followers · 6535 posts · Server linuxrocks.online

Upgraded my instance to test the work, now I just have to wait for `pkg-static upgrade -fy` to finish working, but so far it's been working great, scrolling text and whatnot :P

#hardenedbsd #retpoline

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

The experimental package build is looking very promising. :)

#hardenedbsd #retpoline

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

12-CURRENT/amd64 experimental package build with enabled globally for world, kernel, and the entire ports tree started. Let's see how this goes!

#hardenedbsd #retpoline

Last updated 8 years ago

Shawn Webb · @lattera
1326 followers · 5171 posts · Server bsd.network

For users on the hardened/current/retpoline branch, will be enabled globally for the entire ports tree: github.com/HardenedBSD/hardene

#retpoline #hardenedbsd #meltdown #spectre

Last updated 8 years ago