What is the argument here? Is there something about this randomization that distinguishes it from classic security through obscurity?
What is the argument here? Is there something about this randomization that distinguishes it from classic security through obscurity?
Here are some excellent slides on exploit mitigation in general: https://events.yandex.com/events/ruBSD/2013/talks/103/
Of the top of my head there are four approaches to stopping memory vulnerabilities:
1) have no bugs, e.g. formal verification etc
2) use a memory-safe language
3) accept that there can be vulnerabilities, and use exploit mitigation to harden it
4) capability-based addressing as a mitigation (it doesn't solve use-after-free, for example; it relies on software to do that etc)
Of these, (3) is the one you can retrofit to existing C/C++ codebases... a route you are usually forced to travel.
(There may still be other kinds of bugs, e.g. the obvious sql injections etc; I am talking above about memory bugs specifically)