Can that exploit be trigged without user namespaces? Debian has unprivileged namespaces disabled by default.
Eli Clark
i am compiling kernel... only modules i need... install gentoo
Jaxson Rivera
I am compiling kernel...only modules I need... only modules that are under a free license.... Install gentoo
Ethan Moore
I can't do this luxury thanks to broadscum.
Lucas Robinson
Nah, I don't stay on bleeding edge, I update when I'm bored or a major security vulnerability is found, either way all I need to do is copy my config, set any new settings that are available and let it compile.
Josiah Young
Wouldn't that cause issues if you actually use "Linux on the Desktop"
Robert Long
I'm guessing companies who refuse to put down their 80386 servers?
Grayson Wood
Hardening and defense in depth is a waste of time. It's rare for someone to use a 0day against regular people. If someone wants you bad enough, they'll find a vulnerability in whatever you use
Just keep everything up to date. These vulnerabilities are only an issue after they disclosed.
Logan Williams
compile you own kernel, for example gentoo's default kernel sources have majority of things disabled... you just enable things you need and thats it... compilation takes 4-5 mins everytime i am upgrading to newer kernel version
Adrian Parker
Compiling the Linux kernel actually is pretty fast. Try to compile firefox, I still don't know if it's possible at all.
Eli Hernandez
i have compiled palemoon myself one time, it took about one and half hour on q6600 cpu... for firefox you need to have bunch of RAM
Jace King
Top 4 longest turds to compile on Gentoo: 1. LibreOffice 2. Firefox 3. Webkit 4. Qt
Ian Barnes
Came to post this. If you know what your hardware needs, configuring a kernel is a one-time affair and solves exactly this problem.
And they say C++'s shitty compile times don't matter. LLVM deserves a mention, I need that thing for my graphics card and holy shit do I love waiting for 1300 C++ files.
Josiah Morgan
They are not in the Windows 10 kernel. :)
Daniel Thompson
C++'s compile times don't matter when it's possible to farm out the process to many machines.