Earlier quoted context omitted.
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
Oracle has a track record of being The Worst about anything.
VirtualBox E1000 Guest-to-Host Escape
91–100 of 118 posts
Re: VirtualBox E1000 Guest-to-Host Escape
#92Earlier quoted context omitted.
From GP's link: > While the crashing bug was reported to the VirtualBox tracker ( https://www.virtualbox.org/ticket/16444 ), it was never considered a security vulnerability, and is not marked as one. This ticket is 15 months old at the time of writing this post and still marked as unresolved. They might not be The Worst, but at 15 months, they're not great.
The text of the bug doesn't have any suggestion of it being a vulnerability and as the closing comment indicates, not enough information to reproduce
Re: VirtualBox E1000 Guest-to-Host Escape
#93Earlier quoted context omitted.
From GP's link: > While the crashing bug was reported to the VirtualBox tracker ( https://www.virtualbox.org/ticket/16444 ), it was never considered a security vulnerability, and is not marked as one. This ticket is 15 months old at the time of writing this post and still marked as unresolved. They might not be The Worst, but at 15 months, they're not great.
The text of the bug doesn't have any suggestion of it being a vulnerability and as the closing comment indicates, not enough information to reproduce
Very, very rarely will a Sev1 crash in production software be instantly reproducible. When it is, it’s an utter embarrassment. More often the full set of conditions which lead to the crash are unknown, rare, and hard to fully quantify all at once.
And yet, we know with certainty that the crash did happen and by definition it is a valid bug in any sane world where “don’t crash” is an absolute requirement.
Any crashing bug in a hypervisor must be assumed to be security critical until proven otherwise. Even after “proving” a crash can’t possibly be exploited, you should still assume that a clever attacker will figure out a way. The Venn diagram of “crashing bugs” and “security exploits” is vanishingly disjoint.
Re: VirtualBox E1000 Guest-to-Host Escape
#94Earlier quoted context omitted.
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
"You need to think of Larry Ellison the way you think of a lawnmower. You don't anthropomorphize your lawnmower, the lawnmower just mows the lawn, you stick your hand in there and it'll chop it off, the end. You don't think 'oh, the lawnmower hates me' -- lawnmower doesn't give a shit about you, lawnmower can't hate you. Don't anthropomorphize the lawnmower. Don't fall into that trap about Oracle."
Re: VirtualBox E1000 Guest-to-Host Escape
#95Earlier quoted context omitted.
The text of the bug doesn't have any suggestion of it being a vulnerability and as the closing comment indicates, not enough information to reproduce
“Unreproducible” can also be read as “Wasn’t worth the effort to reproduce”. Very, very rarely will a Sev1 crash in production software be instantly reproducible. When it is, it’s an utter embarrassment. More often the full set of conditions which lead to the crash are unknown, rare, and hard to fully quantify all at once. And yet, we know with certainty that the crash did happen and by definition it is a valid bug i…
If you absolutely can't crash, you need to build an OS that caters to that - modern OSes explicitly prioritize other goals, like performance
Re: VirtualBox E1000 Guest-to-Host Escape
#96Earlier quoted context omitted.
There are plenty of other big companies behaving similarly. HP comes to my mind also, but I cannot find the statistics which quantified worst maintainance practices.
Other companies may be behaving similarly, but Oracle is the perceived worst, and it says something. Because, they plainly don't hide it and try to be nice, at least. I also think that they're the worst in the industry.
My personal bias would also tell me Oracle is because of their business practices, but we were arguing about support practices.
Re: VirtualBox E1000 Guest-to-Host Escape
#97Re: VirtualBox E1000 Guest-to-Host Escape
#98Earlier quoted context omitted.
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
Oracle has a track record of being The Worst about anything.
But that's about it.
Re: VirtualBox E1000 Guest-to-Host Escape
#99Earlier quoted context omitted.
Other companies may be behaving similarly, but Oracle is the perceived worst, and it says something. Because, they plainly don't hide it and try to be nice, at least. I also think that they're the worst in the industry.
I said there was a study which did quantify worst maintainance practices: time to fix bugs, time to reply and several other support metrics and interestingly Oracle was not the worst, HP was. My personal bias would also tell me Oracle is because of their business practices, but we were arguing about support practices.
My perceived worst definition was not about only business practices BTW. I meant in every category.
Nonetheless, supporting the products you sold are also a business. :)
Re: VirtualBox E1000 Guest-to-Host Escape
#100Earlier quoted context omitted.
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
Oracle has a track record of being The Worst about anything.