Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'd compare it to a classical steering-wheel lock. It makes your car a bit harder to steal. Even without it, a thief would still have to get into the car and start the engine. But not parking in a bad neighborhood will likely be a more important factor.

ASLR makes it harder to exploit other bugs that might exist in the software. Browser for example should definitively use it, since they are highly complex systems while also your first line of defense against a somewhat competent attacker. As for 7zip... it also can come in contact with dubious files quite easily while also having to support lots of formats (huge attack surface with potential bugs). I'm torn, but would probably prefer it to use ASLR.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: