Live data from Hacker News

CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

lists.thekelleys.org.uk

221–230 of 256 posts

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#221

Earlier quoted context omitted.

Well, I don't see them in HN is what I am saying. Obviously not scanning 24/7 but every time I enter an HN thread where Rust is even loosely mentioned, I brace for the inevitable bullies imagining they are victims. And this thread is exactly the same, sadly. I am genuinely curious where this fanatic group is. Where are you witnessing them?

> I brace for the inevitable bullies imagining they are victims. As a person who is bullied physically, verbally and emotionally for years, I'd not throw words bully/victim like wrapping paper like that. Moreover, I'd never bully anyone. I'm not that . > I am genuinely curious where this fanatic group is. Where are you witnessing them? Discord servers, mailing lists, issue threads, discussions, here and there. They a…

> As a person who is bullied physically, verbally and emotionally for years, I'd not throw words bully/victim like wrapping paper like that. Moreover, I'd never bully anyone. I'm not that.

I was bullied as well. Knowing karate and aikido helped but not much, those people just hated me for reasons I never quite understood and kept coming in groups even. Some days I wondered whether I'll go back home from school alive. However, me entering middle age has me almost not caring anymore about the reasons they were like that, so I got that going for me which is nice.

I am not "throwing" words. I believe I know what I am talking about because I witnessed a few bullies wisening up to losing prestige and status for being rightfully called out and learning to pretend they are the victims... and it worked in part. It was sickening then, it's sickening now, wherever I spot it. HN is one of those places.

And btw I was not talking about you. You seem more reasonable than f.ex. this poster under my comment here: https://news.ycombinator.com/item?id=48123734

> Discord servers, mailing lists, issue threads, discussions, here and there. They are very vocal and abrasive minority, but it's enough to make me stay away from them.

OK, I'll admit ignorance because I don't go to any of those places or at least it's very rare.

One thing jumps at me: you are avoiding those people which is 100% fair and I would as well. But why avoid Rust itself? Why look down on any rewrite-in-Rust initiatives? Why do you allow yourself be emotionally manipulated? Would you stop believing in your favorite alternative-energy or alternative-engine approaches if they had the 0.1% toxic zealots screaming for attention on events dedicated to those areas?

I can somewhat relate, mind you. One example: I hated how everyone was trying to make me read some book classics and basically made it a point to avoid them just based on that. I was fully aware that was an irrational reaction that was likely robbing me of enjoying good art. I take big pride in myself for finally overcoming this some 2-3 years ago and starting to go through those books. They were nothing special, mind you, and I still couldn't see why people deem most of them classics but at least now my opinion is my own and built with my own two eyes and brain.

> Make no mistake: My favorite languages have the same fanatics, and I stay away from them, too.

Well, that by itself seems to close the discussion. You are aware of this nuance.

> Maybe one day I'll start writing Rust, after gccrs stabilizes (they're going well) or really start writing lisp, but I'm sure that I'll never ask a question to a mere mortal about programming either language.

I refuse to feel shame about wanting to learn and absorb other people's expertise. If somebody is being an arse about it then it's them who are embarrassing themselves; not me. But I do agree it's a waste of time and I'll admit nowadays I start with an LLM session and only then branch out to people if I feel unsatisfied. But that's a function of how awfully busy I am and not that I am becoming more antisocial. (Which also explains I dissociated for 1-2h and preferred to read HN or a book.)

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#222

Earlier quoted context omitted.

That is a very pretentious opinion. Dnsmasq is a ubiquitous project, ~14 years old, and has maintainers that are very experienced in c and in the codebase. Telling them to rewrite in a language they are (maybe) unfamiliar with, even with the help of AI, will make these maintainers' experience worthless. People seem to think that rewriting in rust just magically fixes all issues, but that's not how it works (See recen…

I think I was ambiguous. > If it was so easy to rewrite everything in rust, I don't know why the response to this incidents isn't a rock solid replacement in rust, the next day. Meaning that AI/Rust enthusiasts are supposed to supply solutions. Of course they won't.

But they will produce a lot of posts on this website to say that it's only 3 weeks away.

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#223
post #200

Earlier quoted context omitted.

> I don't know why the response to this incidents isn't a rock solid replacement in rust, the next day. Go ahead and ask your AI to make it. What's stopping you?

> What's stopping you? Based on their comment I guess they are worried they won't earn enough stars on github

They can simply buy them :D

At a talk to showcase how dumb stars/downloads are to measure popularity I showcased a tool to reach the most downloaded list very easily.

The owners of code repositories that release download counts stats without even aggregating them by IP address are fully aware of it.

Probably some people play the stats to seem popular and get VC funding.

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#224
post #134

Earlier quoted context omitted.

The question is whether the current situation is a short burst of action, and once those most critical bugs get fixed the hype around AI vulnerability scanning will die down, or whether the current crop of system/infra software written in vulnerable languages like C are beyond redemption and they will provide an endless source of critical bugs for AI to find until we fix them by rewriting them in Rust/Go/whatever.

An eternal summer of CVEs is upon us

https://www.securityweek.com/tanstack-mistral-ai-uipath-hit-...

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#225
post #93

Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes. But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it. Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broke…

That's what stable is for though. Like, sure, stable's policy is ludicrous and you would have to be insane to run stable. But the remedy for that isn't to try to change Debian policy, it's to get people to stop running stable. Maybe once no-one uses it Debian will see sense.

Yep, let's all use libraries that change API every day instead. That will be more productive.

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#226

Maybe this is the kick in the ass Debian needs to upgrade the embarrassingly ancient dnsmasq in "stable" because while I can't think of any new features, the latest versions contain many non-CVE bug fixes. But I doubt it, they will lazily backport these patches to create some frankenstein one-off version and be done with it. Before anyone says "tHaT's wHaT sTaBlE iS fOr": they have literally shipped straight-up broke…

> they have literally shipped straight-up broken packages before

And did you open a high severity bug or you just kept it to yourself until you came here to complain years after the fact?

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#227
post #199

Earlier quoted context omitted.

But removing all the memory footguns while introducing hundreds of syscalls footguns where rust won't help you at all might not be better at all,

I agree, absolutely. Hence my adjacent thought that maybe all this should just be thrown away and we should invent an FS with ACID semantics. I'm all for gradual improvements but at one point and on we should zoom even further out and pick our battles well.

If we are going so far to only guarantee correctness if we are using a FS that implements ACID semantics, why not just reinvent the whole kernel and remove all footguns, including memory safety? We could have a OS that each syscall to memory allocation can only be done through safe API.

Otherwise, it doesn't really make sense. The only reason we have things like Rust and other memory safe languages is because we want to create safer programs in the existing imperfect OSes that we have currently.

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#228

Earlier quoted context omitted.

> dnsmasq has served me well for like an eternity in multiple setups for different use cases. As all software it has bugs. And once located those get fixed. Its author is also easy to communicate with. I concur. The last part, however, is quite worrisome. Dnsmasq is ran by one person, published on their own git and I did not see any information about other maintainers. It is a super important (and great, and useful,…

[flagged]

Please don't post insinuations about astroturfing, shilling, brigading, foreign agents, and the like. It degrades discussion and is usually mistaken. If you're worried about abuse, email hn@ycombinator.com and we'll look at the data.

https://news.ycombinator.com/newsguidelines.html

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#229
post #225
post #93

Earlier quoted context omitted.

That's what stable is for though. Like, sure, stable's policy is ludicrous and you would have to be insane to run stable. But the remedy for that isn't to try to change Debian policy, it's to get people to stop running stable. Maybe once no-one uses it Debian will see sense.

Yep, let's all use libraries that change API every day instead. That will be more productive.

The only thing worse than changing APIs is never changing APIs. Having to use APIs from 5 years ago sucks.

Re: CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq

#230

Earlier quoted context omitted.

Who said it can't? https://news.ycombinator.com/item?id=47759709 appears to be a nearly flawless (per spec) zip implementation.

[flagged]

Could you please stop breaking the site guidelines? We've already asked you once.

https://news.ycombinator.com/newsguidelines.html

Post reply on HN