Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

281–290 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#281
post #116

Earlier quoted context omitted.

Yep, I'd be fine with that. My bank has insurance, and my money would be returned.

Just socialize losses and all is well. What could possibly go wrong?

that is basically how all large companies behave anyway. socialize the losses (bailouts, layoffs, negative economic impacts in the communities they reside, etc.) and privatize the gains.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#282
post #109

Earlier quoted context omitted.

Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.

I'm pretty sure they have a legal obligation in most jurisdictions not to sell 0days for profit. And they absolutely have a moral obligation to do things in a way to minimize damage and impact to other people's systems. (I'm not saying "responsible disclosure" is the correct way to do that, but hoarding vulnerabilities and exploits and selling them to the highest bidder certainly isn't.) This is how society needs to…

It is categorically false that there's a legal obligation not to sell vulnerabilities. There's an obligation not to knowingly sell them directly to ongoing criminal enterprises. That's it. Plenty of people make fuckloads of money selling vulnerabilities for exploitation rather than repair.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#283

Stop blaming the reporter. Start asking kernel to fix their process. Linux kernel is no longer a toy project, it has full time employees employed by various companies. They should have handled notifying distributions. Not some rando.

It's one thing to report a vulnerability, another entirely to make a crazy exploit available for any tom, dick, and harry to take and use. It was irresponsible of whoever came up with it to release it in the world without first giving major distros a head's up.

Bashing on the reporter is pointless feel-good. This is a massive vuln. It was 4 weeks after Kernel had a patch. They had no way to know if others parties had also discovered the vuln. Lord Knows how many millions of systems could already have been rooted. The reporter is not their minion.

If I call 911 to report a fire at an oil storage facility - and they ask me to alert the hospital, then phone the neighboring county's Sheriff Dept., and then...yeah. Either I'm way out in the sticks (and known to/trusted by the 911 operator), or else the 911 service is run by children.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#284

Earlier quoted context omitted.

Sure, maybe it's not a _requirement_, but now we're all in more pain because the reporters are more interested in Fame than Safe Remediation.

No, you're in more pain, but other defenders with different postures benefit from having faster and fuller disclosure.

> No, you're in more pain, but other defenders with different postures benefit from having faster and fuller disclosure.

Good for them. But just because some folks cannot afford 24/7 response teams and on-call personnel that doesn't make them or their systems any less important.

Lots of non-profits and academic institutions had to scramble because of the Linux kernel team's position of non-communication to distros.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#285

Earlier quoted context omitted.

No, you're in more pain, but other defenders with different postures benefit from having faster and fuller disclosure.

> No, you're in more pain, but other defenders with different postures benefit from having faster and fuller disclosure. Good for them. But just because some folks cannot afford 24/7 response teams and on-call personnel that doesn't make them or their systems any less important. Lots of non-profits and academic institutions had to scramble because of the Linux kernel team's position of non-communication to distros.

The conversation about how Linux handle these things is a good and worthy one to have and one "non-profits and academic institutions" need to have when they select distributions. I'm just here to push any of that scrutiny off the vulnerability reporters; Linux is lucky to have them, even if it's mishandling their reports. Vulnerability researchers don't owe these people anything.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#286

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

“Shared hosting providers” These haven’t been a thing since VMs … basically for this reason. There’s always a local privilege exploit.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#287

Earlier quoted context omitted.

If you notify the kernel and they ship a fix, it seems reasonable to expect that they will communicate the fix to the distros. I see this as an organizational failure of the Linux ecosystem. There should be better communication between distro and kernel development.

The reporter clearly knows the distro fixes have not been shipped, read their report. They chose to disclose anyway.

>They chose to disclose anyway.

yes, because 30 days had passed from the time the patch landed in the kernel, as per industry standard.

approximately every security researcher, including the likes of google and other big names you may know, does a 90+30 disclosure, which is what happened here. they do this for good reason, which has been figured out over decades of experience in reporting thousands and thousands of vulnerabilities.

the only security researchers i know of that dont like 90+30 actually argue for shorter timelines (or immediate disclosures).

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#288

Earlier quoted context omitted.

I'm not advocating for delaying the disclosure at all; my point is, if you see your initial disclosure to the kernel didn't go anywhere, to be responsible is to put in a little extra effort to ensure the fix is picked up before you disclose.

"Didn't go anywhere"? The kernel devs patched it! They patched it weeks ago! The kernel security team needs to communicate security problems in their own releases, because that is where the distros are already looking. Requiring the security researcher to do it is insane. Should a security researcher that identifies a vulnerability in electron.js need to identify every possible project using electron.js to communicat…

> Should a security researcher that identifies a vulnerability in electron.js need to identify _every_ possible project using electron.js to communicate with them the vulnerability exists? No. That's absurd.

But this is a false comparison, right? The scope of "Linux distributions" and "electron apps" are orders of magnitude different. If the reporter spot checked one or two of the most popular distributions to see if fixes had been adopted, that seems like an extra level of nice diligence before publicizing the details.

It doesn't seem "insane" as much as "not the most efficient path" as has already been well argued. But it also doesn't seem unreasonable to think in a project of the scope of the Linux kernel, with the potential impact of fairly effective(?) privilege escalation, some extra consideration is reasonable--certainly not "insane" at the very least?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#289
post #288

Earlier quoted context omitted.

"Didn't go anywhere"? The kernel devs patched it! They patched it weeks ago! The kernel security team needs to communicate security problems in their own releases, because that is where the distros are already looking. Requiring the security researcher to do it is insane. Should a security researcher that identifies a vulnerability in electron.js need to identify every possible project using electron.js to communicat…

> Should a security researcher that identifies a vulnerability in electron.js need to identify _every_ possible project using electron.js to communicate with them the vulnerability exists? No. That's absurd. But this is a false comparison, right? The scope of "Linux distributions" and "electron apps" are orders of magnitude different. If the reporter spot checked one or two of the most popular distributions to see if…

They embargoed their vulnerability for 30 days after Linux landed a kernel patch. They did their part. You will always be able to come up with other things they could do for you, and they will always at first blush sound reasonable because of how big and important Linux is, but none of those things will be responsibilities of the vulnerability researcher. Their job is to bring information to light, not to manage downstreams.

About half the thread we're on reads as if the commenters believe Xint made this vulnerability. They did not: they alerted you to it. It was already there.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#290

Earlier quoted context omitted.

> they are in a much better position to coordinate and communicate with the maintainers than random reporters are. They openly refuse to do this and have been given authority by MITRE to work against any such process.

right, which is why it is confusing that the animosity is aimed at the reporters rather than the kernel security team.

Not really confusing. Linux is a sacred cow.

There would be a lot of people gloating if this happened to MS.

Post reply on HN