Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

391–400 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#391

Earlier quoted context omitted.

i have no problem with disclosing a vulnerability 30 days after its patched in the thing you reported to. (in fact, for those unaware, this is the same policy that google's project zero uses: "90+30" https://projectzero.google/vulnerability-disclosure-policy.h... ) the real problem is: > It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. the report…

> a notification should have gone out from the kernel team to a curated list of distro security folk Who would curate that list though? You don't need permission from the kernel team to spin up a new distro. I can go and create fork of Debian or Arch or whatever today and the kernel team would never know (and neither should they). This is completely in the responsibility of the distros. If you don't like this model,…

Uh, there is a list, named "linux-distros", which is for this purpose (and I think it's for more than just Linux, e.g. I believe it was used for the xz vuln).

Given this was announced when backports weren't ready (and given the POC was at least opaque if not obfuscated), I'm getting the vibe fixing the vuln wasn't as high as a priority as making a media splash.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#392

Stop blaming the reporter. Start asking kernel to fix their process. Linux kernel is no longer a toy project, it has full time employees employed by various companies. They should have handled notifying distributions. Not some rando.

Look, if they namedrop specific distros in their announcement (marketing) blog post as affected, I think a heads-up before publishing that is appropriate and expected. I don't think they would have gotten as much flame if it weren't for how the RHEL 14 mention and such were put. This is a security company with a professional(?) communications department banking on pointing fingers at distro maintainers. We are not ta…

Exactly. Any security person absolutely KNOWS that the distros are still going to be vulnerable. They're exploiting this process loophole to knowingly cause chaos and gain notoriety.

At this point this is not really white-hat/ethical hacking anymore.

Ofc the kernel-distro security loophole is stupid and should be patched ASAP, but that doesn't absolve this company of wrongdoing.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#393
post #377

Earlier quoted context omitted.

> a notification should have gone out from the kernel team to a curated list of distro security folk Who would curate that list though? You don't need permission from the kernel team to spin up a new distro. I can go and create fork of Debian or Arch or whatever today and the kernel team would never know (and neither should they). This is completely in the responsibility of the distros. If you don't like this model,…

Sounds like a job for the Linux Foundation maybe? You don't need anyone's permission to make a distro, that's true, but if you notify Debian, Canonical, Fedora, Red Hat and Arch you're covering a very large fraction of users; way more than today's 0%. In cases like this, perfect is the enemy of the good.

A rogue actor may create a new distro, maybe for some niche use case such as accessibility or retro gaming. After acquiring enough false (and even some real) users that the Linux Foundation accepts them as a notifiable distro maintainer, this maintainer could then pwn machines before the exploit is made public.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#394
post #377

Earlier quoted context omitted.

Sounds like a job for the Linux Foundation maybe? You don't need anyone's permission to make a distro, that's true, but if you notify Debian, Canonical, Fedora, Red Hat and Arch you're covering a very large fraction of users; way more than today's 0%. In cases like this, perfect is the enemy of the good.

A rogue actor may create a new distro, maybe for some niche use case such as accessibility or retro gaming. After acquiring enough false (and even some real) users that the Linux Foundation accepts them as a notifiable distro maintainer, this maintainer could then pwn machines before the exploit is made public.

Rather than the current situation, where they can pwn machines after the exploit is made public?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#395
post #377

Earlier quoted context omitted.

Sounds like a job for the Linux Foundation maybe? You don't need anyone's permission to make a distro, that's true, but if you notify Debian, Canonical, Fedora, Red Hat and Arch you're covering a very large fraction of users; way more than today's 0%. In cases like this, perfect is the enemy of the good.

A rogue actor may create a new distro, maybe for some niche use case such as accessibility or retro gaming. After acquiring enough false (and even some real) users that the Linux Foundation accepts them as a notifiable distro maintainer, this maintainer could then pwn machines before the exploit is made public.

I didn't say all distros should be notified, for that exact reason. I listed a handful of major fistros.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#397

Earlier quoted context omitted.

The title on this post was changed to imply that only the Gentoo developer was left out - which I could believe.

And now it was changed back. I'm goin' insane.

And now it's changed to be a generic "For Linux kernel vulnerabilities" rather than specifically about Copy-Fail.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#398
post #395

Earlier quoted context omitted.

A rogue actor may create a new distro, maybe for some niche use case such as accessibility or retro gaming. After acquiring enough false (and even some real) users that the Linux Foundation accepts them as a notifiable distro maintainer, this maintainer could then pwn machines before the exploit is made public.

I didn't say all distros should be notified, for that exact reason. I listed a handful of major fistros.

Who gets to decide who the lucky few are?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#399
post #114

Earlier quoted context omitted.

It is absolutely not true that viable commercial vulnerability labs need to "accept the norms around responsible disclosure". There are no such norms. "Responsible disclosure" is an Orwellian term cooked up between @Stake and Microsoft and other large vendors to coerce researchers into synchronizing with vendor release schedules. It was fantastically successful at that, and it's worth pushing back on at every opportu…

Microsoft's policy is: "if you contact us with a vulnerability, you automatically agree to the terms of our responsible disclosure policy", which includes waiting 30 days after patch was created, and says nothing about how long that process takes. There is actually no way to give them a friendly heads up, and then do your own thing. The only way not to be bound is by not sending them any notification at all...

> terms of our responsible disclosure policy

I couldn't find a public copy of that.

The best starting point I found for reporting vulnerabilities was: https://github.com/microsoft/MSRC-Security-Research/security...

You can email without agreeing to anything. But for a serious issue Microsoft would obviously try and track down who you are and what jurisdiction you are in.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#400
post #229

Earlier quoted context omitted.

I find it curious to call someone dropping a weaponized root exploit before major distros or even LTS kernel git branches have patches ready "good guys". This could have been handled with much more grace.

Again: I made the actual distinction between bad guys and good guys clear. Good guys don't become bad guys simply because kernel security is an inconvenience to you.

There are more than just good guys and bad guys; in particular, there are also opportunists.

Opportunists are the ones who will sell a 0day to bad guys. Or who will drop a 0day publicly to promote their services. And they’ll fight tooth and nail against any actual legal obligation to engage in responsible and coordinated disclosure, because they make more money without that.

Post reply on HN