huh somehow seeing people not using ai to work is like wow moment which i cherish a lot these days
For Linux kernel vulnerabilities, there is no heads-up to distributions
251–260 of 578 posts
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#252Earlier quoted context omitted.
No, it's incompetence from everyone involved except the company making the disclosure , which, despite the fact that the existing norms are not in fact binding (like people downthread seem to believe), they followed.
Really? It seems very odd to not check in on the status of the fixes, even if it's technically possible to pass the blame to other people. Even if the only purpose of looking at the status to make yourself look good in marketing materials, it's surprising that it didn't happen.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#253Earlier quoted context omitted.
Two things can be true simultaneously: the Linux kernel ecosystem should have done better at communicating this to their downstreams, and publicly sharing the exploit was irresponsible. It is not the responsibility of the initial reporter to communicate to distributions, but the fact that those responsible failed to do that, doesn't give everybody else a free pass.
No, this was already timed disclosure. This is very common and widely accepted. 90+30 is what Google Project Zero uses, for example. The security researcher has met their ethical requirements already. This is entirely on the kernel's security team for failure to communicate downstream. That is their responsibility. The thing is, malicous actors are already monitoring most major projects and doing either source analys…
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#254Earlier quoted context omitted.
No, you're in more pain, but other defenders with different postures benefit from having faster and fuller disclosure.
Mind explaining how sitting on it a month after the patch landed is 'faster'? To my mind, that's a month where attackers could analyze commit logs, but maintainers are not acting with urgency to ship fixes.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#255Earlier quoted context omitted.
No: your posture with respect to having to cycle servers is a super complicated subject and you address it both with process and with architecture (for instance: you can be blasé about things like CopyFail if you don't allow multitenant shared-kernel in your design in the first place). But no matter what process and design you have, if you're hosting sensitive workloads, you always have to be in a position where you…
I find it curious to call someone dropping a weaponized root exploit before major distros or even LTS kernel git branches have patches ready "good guys". This could have been handled with much more grace.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#256Earlier quoted context omitted.
i have no problem with disclosing a vulnerability 30 days after its patched in the thing you reported to. (in fact, for those unaware, this is the same policy that google's project zero uses: "90+30" https://projectzero.google/vulnerability-disclosure-policy.h... ) the real problem is: > It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. the report…
Two things can be true simultaneously: the Linux kernel ecosystem should have done better at communicating this to their downstreams, and publicly sharing the exploit was irresponsible. It is not the responsibility of the initial reporter to communicate to distributions, but the fact that those responsible failed to do that, doesn't give everybody else a free pass.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#257Earlier quoted context omitted.
Mind explaining how sitting on it a month after the patch landed is 'faster'? To my mind, that's a month where attackers could analyze commit logs, but maintainers are not acting with urgency to ship fixes.
No, I wouldn't, because my own preferences are towards immediate disclosure. Tavis Ormandy dropped Zenbleed out of the sky onto us. It wasn't comfortable, it was a scramble for us, but I don't blame Tavis for it; he made a principled call. Better that people know, than that information be concealed from them while designated elites perform a process.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#258Earlier quoted context omitted.
No, I wouldn't, because my own preferences are towards immediate disclosure. Tavis Ormandy dropped Zenbleed out of the sky onto us. It wasn't comfortable, it was a scramble for us, but I don't blame Tavis for it; he made a principled call. Better that people know, than that information be concealed from them while designated elites perform a process.
I'd also prefer immediate disclosure, but I don't get how waiting a month without telling anyone is good regardless of which side you land on.
wait, what?
you are in another comment thread, of this very post, calling these reporters bumbling and incompetent for their disclosure. "merely bumblingly incompetent and overly eager to get their marketing pitch out the door" - that is your quote.
you also said "Basic care would involve making sure the patches had made it into the wild before ending the embargo", which is the literal opposite of immediate disclosure.
but now you are saying they should have just dropped it with no reporting at all? because that is what "immediate disclosure" means. pop up the exploit script on twitter and call it done.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#259Earlier quoted context omitted.
Who cares about how you are seen when you are selling 0day for big bucks? The bad actor makes more money than the 'legitimate' one without breaking any law. Punishing someone who didn't alert distros despite a patch being available encourages the company to simply find flaws and sell them for profit - it pays more to begin with.
it’s called building and preserving a high trust society, you wouldn’t understand
Those private actors aren't planning to sit around and hold onto these exploits they've horded forevermore, they're obviously paying for them so they can one day use them.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#260Earlier quoted context omitted.
The worst thing would be to exploit or sell it for profit. Instead of that, publicizing the exploit is closer to neutral–good in my books, that did trigger a really quick reaction from the different actors to patch their kernels and systems
Imagine how much quicker the distros would have reacted if they were given a heads up a month ago. But, sure, I guess kudos to this company for not being actively criminal, and merely bumblingly incompetent and overly eager to get their marketing pitch out the door.
The kernel security team was given the heads up a month ago. At that point it is their decision.