Hey all,
Our company just had a technical security validation team that gave us a recommendation to move from FreeBSD to different OS to "solve this problem".
Here is the verbiage of what they found:
How they determined it was not disclosed, and not a fight I can stand on. The higher-ups are looking at me to answer this and assure them FreeBSD is okay, otherwise they are going to move us to another OS.
Please help, our shop has way too much time and effort put into our FreeBSD architecture to just move away. Documentation is what they need, something more formal, not just opinion please.
SK
Our company just had a technical security validation team that gave us a recommendation to move from FreeBSD to different OS to "solve this problem".
Here is the verbiage of what they found:
"Object reuse cannot be verified:
FreeBSD cannot be verified that the operating system ensures transient memory cleansing (object reuse) features are in place. The Validation team has determined this to be a finding. By using this Operating System (OS) which does not ensure that no residual data from a former object exists, a malicious user could gain access to memory and OS objects that contain information. "
How they determined it was not disclosed, and not a fight I can stand on. The higher-ups are looking at me to answer this and assure them FreeBSD is okay, otherwise they are going to move us to another OS.
Please help, our shop has way too much time and effort put into our FreeBSD architecture to just move away. Documentation is what they need, something more formal, not just opinion please.
SK