Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

261–270 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#261

Earlier quoted context omitted.

Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.

> are free to sell 0day for profit. This is not true in many jurisdictions.

Are you claiming that if I sell 0day through a broker to the national Government of a given jurisdictions that the national Government of that jurisdiction is going to criminally penalize me?

If so, that's a bit naive. In the actual world, that buyer wants to buy more stuff from me, not penalize me.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#262

Hey Xint Code / tylerni7 https://news.ycombinator.com/threads?id=tylerni7 >, maybe you should improve your disclosure process as well? Maybe make it mandatory for users of your tool?

they disclosed 30 days after the patch was merged in the thing they reported to. its the same disclosure policy as google's project zero, and several other major players, so you should probably be trying to ping a lot more people reporters should not be responsible for finding out and individually reporting to every downstream consumer. blame the kernel security team, who is in a much better position to coordinate no…

In the original thread they admitted multiple times that they rushed it out for marketing reasons.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#263
post #93

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

Without taking a position on the disclosure mechanics: any hosting provider hacked with this was already playing to lose. It is not OK to run competing untrusted tenant workloads under a single shared kernel. Kernel LPEs are not rare. This was a particularly simple and portable one, but the underlying raw capability is a CNE commodity.

[deleted]

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#264

Stop blaming the reporter. Start asking kernel to fix their process. Linux kernel is no longer a toy project, it has full time employees employed by various companies. They should have handled notifying distributions. Not some rando.

It's one thing to report a vulnerability, another entirely to make a crazy exploit available for any tom, dick, and harry to take and use. It was irresponsible of whoever came up with it to release it in the world without first giving major distros a head's up.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#265

Earlier quoted context omitted.

No, this was already timed disclosure. This is very common and widely accepted. 90+30 is what Google Project Zero uses, for example. The security researcher has met their ethical requirements already. This is entirely on the kernel's security team for failure to communicate downstream. That is their responsibility. The thing is, malicous actors are already monitoring most major projects and doing either source analys…

I'm not advocating for delaying the disclosure at all; my point is, if you see your initial disclosure to the kernel didn't go anywhere, to be responsible is to put in a little extra effort to ensure the fix is picked up before you disclose.

"Didn't go anywhere"? The kernel devs patched it! They patched it weeks ago! The kernel security team needs to communicate security problems in their own releases, because that is where the distros are already looking.

Requiring the security researcher to do it is insane. Should a security researcher that identifies a vulnerability in electron.js need to identify every possible project using electron.js to communicate with them the vulnerability exists? No. That's absurd.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#266

Earlier quoted context omitted.

they disclosed 30 days after the patch was merged in the thing they reported to. its the same disclosure policy as google's project zero, and several other major players, so you should probably be trying to ping a lot more people reporters should not be responsible for finding out and individually reporting to every downstream consumer. blame the kernel security team, who is in a much better position to coordinate no…

In the original thread they admitted multiple times that they rushed it out for marketing reasons.

as an explanation for the misnumbered redhat version.

the disclosure itself followed a normal timeline, which you can view at the bottom of their blog post.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#267

Earlier quoted context omitted.

In my world, responsibility is not just checking a box of following industry practice. Responsibility, as Wikipedia puts it on their social responsibility page, is working together with others for the benefit of the community. And yes, sometimes that's a bit larger burden than would ideally be the case. It's an imperfect world, after all -- and let's not forget the disclosure as it happened also placed a larger burde…

No. The problem is that vendors and developers have repeatedly shown that if you give them an inch, they take a mile. Look at exactly what happened with BlueHammer this month. The security researcher went full disclosure because Microsoft didn't listen to their reports. Disclosure is vital. It's essential . Because the truth is, if a security researcher has found it, it's extremely likely that it's already been found…

> The problem is that vendors and developers have repeatedly shown that if you give them an inch, they take a mile.

[citation needed]

Is there any evidence that Linux distros (specifically) act in this way? Or a particular distro?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#268

Stop blaming the reporter. Start asking kernel to fix their process. Linux kernel is no longer a toy project, it has full time employees employed by various companies. They should have handled notifying distributions. Not some rando.

No, I will. The distros and the kernel devs should be talking and moving on high sev patches, sure. But real people will have gotten hurt because the reporter didn't want to wait for that to happen. That's on them.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#269

Earlier quoted context omitted.

The kernel team has been at odds with the CVE process and the oss-security community about this stuff for many, many years now. It's a big part of why the kernel team established a CNA and started flooding CVE notifications; they don't believe that security problems are different than non-security problems, and refuse to establish norms or policies based on the idea that they are.

It's such a bizarre viewpoint. I wonder when Linus will see sense. IMO it's pretty obviously not a view that they seriously hold, it's just one of those technical justifications people come up with to avoid admitting something they don't want to admit - in this case that Linux has a poor security track record.

Linus? You mean, the same Linus who thinks "security people are f*cking morons", and "security bugs are just bugs"?

Linus is the reason why kernel team doesn't talk to distros. For them bugs are bugs, security related or not.

https://lkml.iu.edu/hypermail/linux/kernel/1711.2/01701.html...

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#270

Earlier quoted context omitted.

No. The problem is that vendors and developers have repeatedly shown that if you give them an inch, they take a mile. Look at exactly what happened with BlueHammer this month. The security researcher went full disclosure because Microsoft didn't listen to their reports. Disclosure is vital. It's essential . Because the truth is, if a security researcher has found it, it's extremely likely that it's already been found…

> The problem is that vendors and developers have repeatedly shown that if you give them an inch, they take a mile. [citation needed] Is there any evidence that Linux distros (specifically) act in this way? Or a particular distro ?

>[citation needed]

there is ~3 decades of citations you can look at, spread out over every security mailing list, security conference, etc. that you can think of.

one decent start is https://projectzero.google/vulnerability-disclosure-faq.html...

"Prior to Project Zero our researchers had tried a number of different disclosure policies, such as coordinated vulnerability disclosure. [...] "We used this model of disclosure for over a decade, and the results weren’t particularly compelling. Many fixes took over six months to be released, while some of our vulnerability reports went unfixed entirely! We were optimistic that vendors could do better, but we weren’t seeing the improvements to internal triage, patch development, testing, and release processes that we knew would provide the most benefit to users.

[...]

While every vulnerability disclosure policy has certain pros and cons, Project Zero has concluded that a 90-day disclosure deadline policy is currently the best option available for user security. Based on our experiences with using this policy for multiple years across thousands of vulnerability reports, we can say that we’re very satisfied with the results.

[...]

For example, we observed a 40% faster response time from one software vendor when comparing bugs reported against the same target over a 7-year period, while another software vendor doubled the regularity of their security updates in response to our policy."

>Linux distros (specifically) act in this way

carving out special exceptions based on nebulous criteria is a bad idea. 90+30 is what has been settled on, and mostly works.

Post reply on HN