Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 519998 - New Kernel Knock patch against NSA portscanning should be included in gentoo
Summary: New Kernel Knock patch against NSA portscanning should be included in gentoo
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Core system (show other bugs)
Hardware: All Linux
: Normal enhancement
Assignee: Gentoo Kernel Bug Wranglers and Kernel Maintainers
URL: http://thread.gmane.org/gmane.linux.n...
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-08-15 15:19 UTC by Benjamin Schulz
Modified: 2014-10-14 17:13 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Benjamin Schulz 2014-08-15 15:19:10 UTC
There is this new  revelation 

http://www.heise.de/ct/artikel/NSA-GCHQ-The-HACIENDA-Program-for-Internet-Colonization-2292681.html 

that NSA/GCHQ and others are massively using port scans to overtake thousands of vulnerable servers, in order to use them as base points to start their attacks.

The article above proposes a kernel patch against this which can minimize attack surfaces a bit. This patch can be downloaded here:

https://gnunet.org/knock

The patch was announced at Gnu Hackers conference today 

https://www.gnu.org/ghm/upcoming.html 

I think it should be included in gentoo kernels.

Reproducible: Always
Comment 1 Agostino Sarubbo gentoo-dev 2014-08-16 07:57:36 UTC
I guess it is not a vulnerability, CC'ing kernel@
Comment 2 Mike Pagano gentoo-dev 2014-10-14 17:13:12 UTC
This was not well received upstream including the possibility of opening new security holes.

I would like to see this discussion go in a way different direction before we could consider it for inclusion.