Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

311–320 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#311
post #130

Earlier quoted context omitted.

“The choice that maximizes potential damage isn’t irresponsible, because it means I can mitigate my own systems immediately.” That’s what you’re saying here.

What the heck is up with people today. Using quotes around something where you’re actually doing a strawman paraphrase of another commenter you disagree with is bad form.

It was clear that the original comment didn't say that, since we can see it right above. It was clear to me that the GP was using quotes as a way to use direct speech, not to imply that the GP literally said those words.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#312

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

There is no such thing as irresponsible disclosure. Thanks though.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#313

Earlier quoted context omitted.

right, which is why it is confusing that the animosity is aimed at the reporters rather than the kernel security team.

Not really confusing. Linux is a sacred cow. There would be a lot of people gloating if this happened to MS.

Microsoft has a long and sordid history of cheerfully doing anything they can to fuck everyone over just to make a few more percentage points of profit.

Linux is a free kernel that literally revolutionized the computing landscape.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#314
post #281

Earlier quoted context omitted.

Just socialize losses and all is well. What could possibly go wrong?

that is basically how all large companies behave anyway. socialize the losses (bailouts, layoffs, negative economic impacts in the communities they reside, etc.) and privatize the gains.

> that is basically how all large companies behave anyway

And do you agree with that behaviour?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#315

Earlier quoted context omitted.

The kernel team has been at odds with the CVE process and the oss-security community about this stuff for many, many years now. It's a big part of why the kernel team established a CNA and started flooding CVE notifications; they don't believe that security problems are different than non-security problems, and refuse to establish norms or policies based on the idea that they are.

It's such a bizarre viewpoint. I wonder when Linus will see sense. IMO it's pretty obviously not a view that they seriously hold, it's just one of those technical justifications people come up with to avoid admitting something they don't want to admit - in this case that Linux has a poor security track record.

I think it's an extension of the premise that you should just be taking the whole stable tree with all its patches constantly, whether they're labeled as security fixes or not, because you can never really know for sure some bugs weren't security bugs.

I don't agree with the premise, but I do think it's a sincerely held one.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#316

Earlier quoted context omitted.

It is literally not the vulnerability researcher's problem to solve or address this.

Agree, but then where does the accountability lie? Presumably with the kernel maintainers themselves, correct? SOMEONE dropped the ball here. If we can't point the finger correctly, that seems like a problem in of itself.

It looks like the expected thing happened.

The kernel devs patched the kernel. The kernel devs have a pretty known, straightforward stance in how they ship fixes for anything, because anything in the kernel can be a security problem.

Distro maintainers can see kernel changes. Some distros aggressively track new changes. Others backport what they feel are relevant. Others don’t do either.

Users pick what distro they use, and how they set up their infra.

Maybe if I were paying for RHEL licenses I’d be eyeballing the money I pay and RHEL’s response time.

But the ownership here lies with system operators, who pick their infrastructure, who design their security model, and who build their operational workflows. This vuln is a great example: people who looked at shared untrusted workloads on a single kernel and said “Hell no” had a much calmer day than teams who thought that was a good idea.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#317
post #31

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

The disclosure was more about marketing than security. From the disclosure page: > Is your software AI-era safe? > Copy Fail was surfaced by Xint Code about an hour of scan time against the Linux crypto/ subsystem. [...] > [Try Xint Code] More chaos makes their product seem even more attractive.

To be clear, the vulnerability existed in Linux, not in Xint Code. It existed whether this group disclosed it or not. Knowledge of it and exploits may have already been bought and sold among various groups with various motives including crime, terrorism, or cyberwarfare who likely made good money off it if this happened.

In that world, the vulnerability has more value to those who seek to exploit it for their own motives, regardless of the consequences. They hope that no one else stumbles on it and fixes it, preventing them from continuing to use it to do bad things.

In the world where it is disclosed, there is more value in fixing the vulnerability as the maintainer’s reputation is at risk (and potentially monetary loss or legal liability if they are shown to be negligent).

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#318
post #32

Earlier quoted context omitted.

Your advertising for them on HN would help them too, I bet.

Does it? Now that I see their name again in this context they're blacklisted for life.

What are they blacklisted from exactly? The benefit you get from them forcing vendors to make their software more secure?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#319

Earlier quoted context omitted.

In the original thread they admitted multiple times that they rushed it out for marketing reasons.

as an explanation for the misnumbered redhat version. the disclosure itself followed a normal timeline, which you can view at the bottom of their blog post.

[deleted]
Post reply on HN