|
|
|
|
|
by wahern
1213 days ago
|
|
> Either the attacker has arbitrary code execution [...] or they don’t. That's beyond reductive, even if we grant this website's fundamental premise which rejects economic cost analysis in threat mitigation. Many of the articles on this website are like that--1) it's possible (and even inevitable with sufficient effort) to circumvent mitigation X, therefore 2) mitigation X has no value. That's a huge logical leap that the author (authors?) often cover up with, "Trust me, I develop exploits". EDIT: In case the post is changed, the full quote is, "Either the attacker has arbitrary code execution, and can ROP their way to the 'SPECIFIC execve entry point', or they don't." |
|
I could kind of see the value of this if the above mitigations didn't exist, but as far as I'm aware, they're already pervasive on OpenBSD.