Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

the security benefit of things like stack canaries rest on them being random and not known beforehand, I guess. Otherwise stack smashing malware could know to avoid them.


Wait, how is that relevant? Nothing says stack canaries have to use the same RNG as the main program, let alone the same seed, and there are cases such as this one where they probably shouldn’t, so it makes sense to separate them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: