As I understand it, previous ROP-gadget hardening included compiler modifications on system/function call return, trap sleds, and some other stuff that I don't remember. This is on top of the kernel and library relink at every boot (to really make ASLR more potent).
These modifications include a verification that the jump is in the stack, and not at the tail of some function (and the other thing eludes my understanding).
These are some OpenBSD references on ROP hardening:
https://undeadly.org/cgi?action=article;sid=20170622065629
https://www.openbsd.org/papers/rop.pdf
https://www.openbsd.org/papers/asiabsdcon2019-rop-paper.pdf
I think that the most notorious exploit of "Return-Oriented Programming" (ROP-gadget) flaws was Solarwinds; I understand that a ROP exploit sealed their fate. Maybe Windows is doing some of this in their kernel.
"At this point, we noticed that Serv-U.dll and RhinoNET.dll both have ASLR support disabled, making them prime locations for ROP gadgets..."
https://www.microsoft.com/security/blog/2021/09/02/a-deep-di...
Am I happy to have ROP safeguards? You bet!
These mitigations don’t really harm anything so they’re not bad, per se, but they’re definitely not particularly impactful when to comes to security so nobody else really thinks it’s worth implementing them. There’s a lot of stuff like this in OpenBSD, but to be fair a lot of other projects are also bad at making mitigations that aren’t very useful. Reading writeups on CTFtime or, heaven forbid, imagining what exploits would look like is sadly too common.
And "This security tech usually..." is a bit too modest. Just one example - OpenBSD is the origin of OpenSSH, which has been rather widely used for a decade or two now.
Since nobody uses protocol 1 anymore, very little of the original code from Tatu Ylönen remains in operation with default settings.
ps I have had to use the SSH commercial release under VMS, and the compatibilities with OpenSSH are quite unpleasant.
That said, this would be great to see in OpenBSD (or any other OS).
Why are these projects that are used by many large and extraordinarily profitable tech enterprises dependent on community donations?
I recommend not donating, because to do so directly supports corporate parasitism.
If a corp wants a feature improved or implemented if it doesn't exist, they will have to pay someone and then they have to decide whether they will contribute it. If they do not, then they have to maintain a fork themselves which requires ongoing resources.
At the end of the day, I don't think it really matters that much. The corps are providing a service not a software application. If they weren't using BSD, they'd be using something else.
And thus the success of BSD-style licensing is thrown into sharp relief. (Also the fact that you or I can go use it as much as we want for free and do whatever we want to it.)
Those days appear to be over.
https://www.theregister.com/2015/07/08/microsoft_donates_to_...
MS : $25k - $50k
Google , FB : $10k - $25k
For them, that's like saying "Hi". For the financial value the OpenBSD foundation is creating, that's a miniscule return.
Still, I haven't heard any recent complaint on fundraising goals.