OpenBSD Will Get Unique Kernels on Each Reboot
bleepingcomputer.com
bleepingcomputer.com
https://marc.info/?l=openbsd-cvs&m=149605105003964&w=2
https://marc.info/?l=openbsd-cvs&m=146168291000757&w=2
This means that in addition to the dynamic linker loading libraries at random addresses, in a random order, the offsets inside the library itself are different on each boot, and on each system.
Robert Peichaer (rpe@) added the kernel re-linking at install/upgrade: https://marc.info/?l=openbsd-cvs&m=149884116824098
The kernel has a similar reordering stage, best explained by Theo de Raadt: https://marc.info/?l=openbsd-tech&m=149887978201230&w=2
The full implementation is in the tree.
^[which?] ^[citation needed]
On mobile, most mobile SoCs include security stuff, Qualcomm seems to have had them since at least the Snapdragon 805. See here for the addition of the RNG to the linux kernel in 2013: https://lwn.net/Articles/570158/
Even common embedded SoCs like those used in the ESP8266 include hardware RNGs.
Really, there's no excuse for not using it as at least one factor. If you're concerned about possible backdoors, xor it with your own CSPRNG in software like the Linux kernel does.
See Theo's talk from Hackfest 2014, an updated talk originally given at EuroBSDcon 2014:
https://www.openbsd.org/papers/hackfest2014-arc4random/index...
Page 19 and beyond explain this in detail: https://www.openbsd.org/papers/hackfest2014-arc4random/mgp00...
This is surely true, but at least on Windows the central security holes do not lie in Windows itself (these kinds of holes exist - but exploits are very expensive, which shows that they are typically rare and not easy to exploit), but in third-party applications.
For example the current 2017 version of the Petya ransomware was spreaded via a security hole in the software update mechanism in the Ukrainian tax preparation software M.E.Doc. Other well-known attack vectors that are commonly used to attack Windows PCs are Flash Player and the Java browser plugin.
It is today considered a design mistake that GDI was moved to kernel mode in Windows NT 4.0 for performance reasons (https://en.wikipedia.org/w/index.php?title=Architecture_of_W...). But with Windows 10 Anniversary Update font parsing is done in user mode within an AC ["AppContainer"] (source: https://blogs.technet.microsoft.com/mmpc/2017/01/13/hardenin...).
This is what many people on the internet say. This does not mean there there might be good arguments for the opposite standpoint, too.
At least I can tell that Microsoft is working to move parts of GDI step by step from the kernel back to user mode again, which should provide evidence that they consider this decision as a historical mistake, too, because it opens too many potential gateways for security flaws.
Or perhaps it was the correct decision at the time, but now (decades on, with computing power orders of magnitude cheaper and security vulnerabilities orders of magnitude more expensive) a different decision is appropriate?
Which ones? I'd be surprised if either of classic MacOS or BeOS didn't have the display layer in the kernel; Solaris had it in userspace but was pretty slow; BSD was still tangled in lawsuits and Linux barely existed.
Yea, but they seemed fast enough with rendering fonts in the userspace (xfstt). Which is what I thought we were talking about.
I don't remember there being enough GUI applications around on Linux/BSD to be able to talk about whether font rendering was fast or slow. Anything that used motif was slow, netscape was very slow. xterm was fast but fixed-font.
(All of the above supports your point; it's just that the Mac went further than you implied.)
Windows NT was a nice, clean system from Dave Cutler, but wouldn't run a lot of code that ran under Windows 95. Especially 16-bit programs, which ran in a compatibility box under NT which was not tolerant of 16-bit programs doing things they were not supposed to be doing. XP put a lot of marginal Windows 95 code in the NT kernel and supported bad 16-bit programs. It took a decade for Microsoft to dig out from that mess.
https://redmondmag.com/articles/2017/06/27/petya-ransomware-...
They don't ? IIRC, stuxnet was an autorun exploit of some kind and the recent unpleasantness was all based on built-in SMB functionality ... right ?
Indeed, but I wanted to illustrate that while kernel security is important, there exist much more dangerous "open barn doors" (I don't know whether this English translation of the German phrase "offene Scheunentore" is proper English).
I still disagree, but less strongly :) Flash has always been a weak point, and Java was (but has not really been hit for a few years). But not only have there been exploits hitting MSIE/Edge/Office, they deserve much of the fault for the poor security architecture that facilitates exploitation of plugins in my opinion. Like untrusted fonts in the kernel, they seem to agree in so far as Edge no longer supports ActiveX at all.
The number of exploits overall has gone way down, but there are still a ton of security patches rated as Critical RCE coming out monthly in all the usual Windows targets. And now that Tavis shone some light on their AV engine, it has been revealed that is a gaping hole both in design as well as in implementation.
Regardless, there are far more practical realities that make Windows a security liability. If you survey 100 random penetration testers, you might find one that uses RCE exploits regularly (before shadowbrokers gave everyone new toys anyway). The playbook for everybody else largely consists of spear phishing to get a "beachhead" and then moving laterally with Pass-the-hash and similar things that are technically possible to defend if you read the documentation and set the right group policies, but that nobody in the real world does.
I'm curious to hear from people working in infosec: is that real problem? How do you see the tradeoff?
Think about this angle: if you're concerned about infosec, and there is a malicious actor with the capability to replace your kernel (which you don't do unless you're root), you do have a real problem. Even if the kernel were verified at boot time, that same actor should have countless other attack vectors.
But it's something worth considering if a tursted chain from machine firmware all the way to the application level is established. It's not there yet.
What is the solution when you need to upgrade some kernel or program and the new version has a different cheksum? I don't see why that same solution, whatever it is, wouldn't work in the relinking case.
Some Linux distributions support kernel and kernel module signature verification in combination with secure boot. As far as I understand, RHEL does this automatically when secure boot is enabled:
https://access.redhat.com/documentation/en-US/Red_Hat_Enterp...
Anyways, with Lenovo who is to say they didn't leak their private key out shear incompetence :)
> "At boot time, a unique kernel is built and installed for the next boot"
Therefore, if the building code is itself trusted it can make a checksum and sign it. So each boot can verify the next boot, in a blockchain-ish way.
If you are in a position to replace the kernel, can't you also replace the code that does this verification?
That is exactly how games are cracked, as I understand.
My best guess: A leaked kernel pointer could be used to find an offset for the KASLR kernel, and that offset could produce a working payload for some other unrelated kernel shell code exploit.
If that's correct, KARL seems like a pretty fringe improvement over KASLR. Can anyone educate me?
Here is a long anti-ASLR rant by the folks who invented the ASLR mitigation in the first place, explaining why attempts to repurpose the idea for kernel attacks are misguided:
https://forums.grsecurity.net/viewtopic.php?f=7&t=3367
I agree that it is probably not a meaningful improvement.
If i understand KARL correctly, they reorder the internal code (and data?) in the kernel. Therefore a single pointer-leak does not expose all the ROP gadgets anymore. More information leak is necessary, or a smaller amount of gadgets. Therefore imho this is a much better protection than KASLR.
If an update does something that breaks your startup sequence it generally is much better to find out about it right away than it is to find out about years later in the middle of the night when you get a forced reboot due to hardware or power issues, and find that things are broken and you have no idea which of a dozen allegedly minor updates broke it.
Can you also detect whether a program will loop forever?
This apps are called static program analyzers and some can prove totality of code.
Assumed the current state of knowledge about our universe no program will loop forever.
But maybe our universe is a kind of infinite loop by itself. Who knows.
An update to foo changes what happens in that undocumented or undefined case, and with the new behavior my application does not start correctly.
There is nothing the package manager can do to ensure that this does not happen because there is nothing wrong with anything the package manager is managing. The bug is entirely in my code. All the update did was expose it.
The question them is when will that now exposed bug actually get hit, so that I become aware of it and fix it.
The purpose of the reboot is to make sure that exposure happens at a time when it will not cause much harm and I will not have a lot of trouble finding it.
Liking the advocacy though
I must admit that syspatch has saved me a ton of time.
Then I laughed some more.
For example, with ASLR, it's easy to retrieve the current layout of the processus and therefore to debug it (if you have the appropriate symbols) despite the randomization. But an exploit has to be built for the specific instance of the application running. If you share the same privileges as the process, you can get the current mapping but an exploit is useless. If you don't, you don't have access to the mapping either and it's difficult to get it while you are executing code inside the process as you can't easily access the functions you would need for that.
e.g. if your stack is hosed, etc, things could be affected
Also, much of kernel debugging involves poking at core images, which wouldn't be coherent with the kernel binary.
That said, I'm fairly certain I recall reading that the logic saves your previous kernel for such a case, and otherwise someone could make scripts to save more copies if needed.
Others have pointed out reconstructing kernels for debug purposes.
"At boot time, a unique kernel is built and installed for the next boot"
Depending on your definition of 'embedded', you might look at the various wireless router repackagings and scripts that are available.. Also, the NetBSD 'rump' kernel might be an interesting thing to review.
Generally speaking, the projects overall have excellent documentation, including manual pages or HTML docs on kernel, c library interfaces, building the system and packages from source, etc. Also, the whole system is in the source tree, which can be downloaded as a set.
Otherwise:
OpenBSD in general: There's "Absolute OpenBSD', kind of more 'user/admin' level.
For lower-level stuff like API's, kernel organization, etc, the McCusick books (Design and implementation of the {4.3BSD,4.4BSD, FreeBSD} Operating System), though either dated, or more specific to FreeBSD, respectively, still cover quite a bit of stuff that still applies to OpenBSD (most changes have been incremental, and can be tracked through the source tree history back to the original USG sources if needed)
I'd suggest running an install 'from source' on a spare machine/vm/etc for a while and reading docs and the source tree this will get you familiar enough with the system to have an idea where to go next.
Unique means something else.
No other OpenBSD installation had or will ever have the same kernel, so each kernel is unique.
If a set has a single member, that member is unique; e.g., 2 is the unique even prime number.
If a thing is different from all other things, it's distinct.
To be fair, your short original post left readers free to guess at which unnecessarily pedantic point you were trying to make.
(It's tautological and uninformative to say that any x is the unique member of the set of things equal to x. And it's simply incorrect to say that any member of a set with multiple elements is unique wrt that set.)