Earlier quoted context omitted.
“The choice that maximizes potential damage isn’t irresponsible, because it means I can mitigate my own systems immediately.” That’s what you’re saying here.
What the heck is up with people today. Using quotes around something where you’re actually doing a strawman paraphrase of another commenter you disagree with is bad form.
For Linux kernel vulnerabilities, there is no heads-up to distributions
311–320 of 578 posts
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#312For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#313Earlier quoted context omitted.
right, which is why it is confusing that the animosity is aimed at the reporters rather than the kernel security team.
Not really confusing. Linux is a sacred cow. There would be a lot of people gloating if this happened to MS.
Linux is a free kernel that literally revolutionized the computing landscape.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#314Earlier quoted context omitted.
Just socialize losses and all is well. What could possibly go wrong?
that is basically how all large companies behave anyway. socialize the losses (bailouts, layoffs, negative economic impacts in the communities they reside, etc.) and privatize the gains.
And do you agree with that behaviour?
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#315Earlier quoted context omitted.
The kernel team has been at odds with the CVE process and the oss-security community about this stuff for many, many years now. It's a big part of why the kernel team established a CNA and started flooding CVE notifications; they don't believe that security problems are different than non-security problems, and refuse to establish norms or policies based on the idea that they are.
It's such a bizarre viewpoint. I wonder when Linus will see sense. IMO it's pretty obviously not a view that they seriously hold, it's just one of those technical justifications people come up with to avoid admitting something they don't want to admit - in this case that Linux has a poor security track record.
I don't agree with the premise, but I do think it's a sincerely held one.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#316Earlier quoted context omitted.
It is literally not the vulnerability researcher's problem to solve or address this.
Agree, but then where does the accountability lie? Presumably with the kernel maintainers themselves, correct? SOMEONE dropped the ball here. If we can't point the finger correctly, that seems like a problem in of itself.
The kernel devs patched the kernel. The kernel devs have a pretty known, straightforward stance in how they ship fixes for anything, because anything in the kernel can be a security problem.
Distro maintainers can see kernel changes. Some distros aggressively track new changes. Others backport what they feel are relevant. Others don’t do either.
Users pick what distro they use, and how they set up their infra.
Maybe if I were paying for RHEL licenses I’d be eyeballing the money I pay and RHEL’s response time.
But the ownership here lies with system operators, who pick their infrastructure, who design their security model, and who build their operational workflows. This vuln is a great example: people who looked at shared untrusted workloads on a single kernel and said “Hell no” had a much calmer day than teams who thought that was a good idea.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#317For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…
The disclosure was more about marketing than security. From the disclosure page: > Is your software AI-era safe? > Copy Fail was surfaced by Xint Code about an hour of scan time against the Linux crypto/ subsystem. [...] > [Try Xint Code] More chaos makes their product seem even more attractive.
In that world, the vulnerability has more value to those who seek to exploit it for their own motives, regardless of the consequences. They hope that no one else stumbles on it and fixes it, preventing them from continuing to use it to do bad things.
In the world where it is disclosed, there is more value in fixing the vulnerability as the maintainer’s reputation is at risk (and potentially monetary loss or legal liability if they are shown to be negligent).
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#318Earlier quoted context omitted.
Your advertising for them on HN would help them too, I bet.
Does it? Now that I see their name again in this context they're blacklisted for life.
Re: For Linux kernel vulnerabilities, there is no heads-up to distributions
#319Earlier quoted context omitted.
In the original thread they admitted multiple times that they rushed it out for marketing reasons.
as an explanation for the misnumbered redhat version. the disclosure itself followed a normal timeline, which you can view at the bottom of their blog post.