Earlier quoted context omitted.
Yep, I'd be fine with that. My bank has insurance, and my money would be returned.
Just socialize losses and all is well. What could possibly go wrong?
For Linux kernel vulnerabilities, there is no heads-up to distributions
281–290 of 578 posts
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#282Earlier quoted context omitted.
Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.
I'm pretty sure they have a legal obligation in most jurisdictions not to sell 0days for profit. And they absolutely have a moral obligation to do things in a way to minimize damage and impact to other people's systems. (I'm not saying "responsible disclosure" is the correct way to do that, but hoarding vulnerabilities and exploits and selling them to the highest bidder certainly isn't.) This is how society needs to…
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#283Stop blaming the reporter. Start asking kernel to fix their process. Linux kernel is no longer a toy project, it has full time employees employed by various companies. They should have handled notifying distributions. Not some rando.
It's one thing to report a vulnerability, another entirely to make a crazy exploit available for any tom, dick, and harry to take and use. It was irresponsible of whoever came up with it to release it in the world without first giving major distros a head's up.
If I call 911 to report a fire at an oil storage facility - and they ask me to alert the hospital, then phone the neighboring county's Sheriff Dept., and then...yeah. Either I'm way out in the sticks (and known to/trusted by the 911 operator), or else the 911 service is run by children.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#284Earlier quoted context omitted.
Sure, maybe it's not a _requirement_, but now we're all in more pain because the reporters are more interested in Fame than Safe Remediation.
No, you're in more pain, but other defenders with different postures benefit from having faster and fuller disclosure.
Good for them. But just because some folks cannot afford 24/7 response teams and on-call personnel that doesn't make them or their systems any less important.
Lots of non-profits and academic institutions had to scramble because of the Linux kernel team's position of non-communication to distros.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#285Earlier quoted context omitted.
No, you're in more pain, but other defenders with different postures benefit from having faster and fuller disclosure.
> No, you're in more pain, but other defenders with different postures benefit from having faster and fuller disclosure. Good for them. But just because some folks cannot afford 24/7 response teams and on-call personnel that doesn't make them or their systems any less important. Lots of non-profits and academic institutions had to scramble because of the Linux kernel team's position of non-communication to distros.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#286For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#287Earlier quoted context omitted.
If you notify the kernel and they ship a fix, it seems reasonable to expect that they will communicate the fix to the distros. I see this as an organizational failure of the Linux ecosystem. There should be better communication between distro and kernel development.
The reporter clearly knows the distro fixes have not been shipped, read their report. They chose to disclose anyway.
yes, because 30 days had passed from the time the patch landed in the kernel, as per industry standard.
approximately every security researcher, including the likes of google and other big names you may know, does a 90+30 disclosure, which is what happened here. they do this for good reason, which has been figured out over decades of experience in reporting thousands and thousands of vulnerabilities.
the only security researchers i know of that dont like 90+30 actually argue for shorter timelines (or immediate disclosures).
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#288Earlier quoted context omitted.
I'm not advocating for delaying the disclosure at all; my point is, if you see your initial disclosure to the kernel didn't go anywhere, to be responsible is to put in a little extra effort to ensure the fix is picked up before you disclose.
"Didn't go anywhere"? The kernel devs patched it! They patched it weeks ago! The kernel security team needs to communicate security problems in their own releases, because that is where the distros are already looking. Requiring the security researcher to do it is insane. Should a security researcher that identifies a vulnerability in electron.js need to identify every possible project using electron.js to communicat…
But this is a false comparison, right? The scope of "Linux distributions" and "electron apps" are orders of magnitude different. If the reporter spot checked one or two of the most popular distributions to see if fixes had been adopted, that seems like an extra level of nice diligence before publicizing the details.
It doesn't seem "insane" as much as "not the most efficient path" as has already been well argued. But it also doesn't seem unreasonable to think in a project of the scope of the Linux kernel, with the potential impact of fairly effective(?) privilege escalation, some extra consideration is reasonable--certainly not "insane" at the very least?
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#289Earlier quoted context omitted.
"Didn't go anywhere"? The kernel devs patched it! They patched it weeks ago! The kernel security team needs to communicate security problems in their own releases, because that is where the distros are already looking. Requiring the security researcher to do it is insane. Should a security researcher that identifies a vulnerability in electron.js need to identify every possible project using electron.js to communicat…
> Should a security researcher that identifies a vulnerability in electron.js need to identify _every_ possible project using electron.js to communicate with them the vulnerability exists? No. That's absurd. But this is a false comparison, right? The scope of "Linux distributions" and "electron apps" are orders of magnitude different. If the reporter spot checked one or two of the most popular distributions to see if…
About half the thread we're on reads as if the commenters believe Xint made this vulnerability. They did not: they alerted you to it. It was already there.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#290Earlier quoted context omitted.
> they are in a much better position to coordinate and communicate with the maintainers than random reporters are. They openly refuse to do this and have been given authority by MITRE to work against any such process.
right, which is why it is confusing that the animosity is aimed at the reporters rather than the kernel security team.
There would be a lot of people gloating if this happened to MS.