Live data from Hacker News

You might want to stop running atop

rachelbythebay.com

41–50 of 155 posts

Re: You might want to stop running atop

#41
post #9

Earlier quoted context omitted.

I'll go with number 3. She didn't just say "don't run", she said "uninstall". That doesn't sound like "misleading" or "uses too much resources". It sounds very CVE-ish.

"uninstall" points at a very specific type of exploit.

Assuming it's actually necessary to uninstall.

It might just be that "uninstall" is the simplest one-word advice you can give that will definitely solve the problem.

Re: You might want to stop running atop

#42
post #39

Earlier quoted context omitted.

It might be covered under an NDA with some company that she's contracting with if she/they discovered the vulnerability in the course of their work.

It could also be any number of other things too, like it's severe enough that the author feels its responsible to wait for mitigation efforts before disclosing anything about the issue that could lead to it being exploited.

The existence and phrasing of this post implies that the author doesn't trust the atop developers to fix anything in a timely manner if at all.

Re: You might want to stop running atop

#43
post #35

Earlier quoted context omitted.

This. Not only that, I don't know of a single person (IRL or online) who used atop, like, ever. In fact, this is the first time I'm even hearing of atop. IIRC, most folks went from top -> htop -> glances -> various btop variants (bashtop, bpytop, btop++ etc)

Btop variants, glances, why should I move from htop?

Why should I move on from top? (serious question)

I'm genuinely stunned to figure out there's a whole set of lore of *tops.

I'm not sure I'm being rational from a textbook security perspective, but, it'd take a whole lot of tangible reward to get me off the binaries supplied with the system.

Re: You might want to stop running atop

#44
post #29
post #11

This screams NDA/disclosure but things are so mega super fucked that they feel obligated to pre warn as early as possible. I wonder how long/old the problem is in atop?

That last line for sure reads as '(author) can't tell you now, but can (plans to) tell you later'; NDA and/or CVE as most likely reasons.

Presumably one step removed? I assume vague-posting would be an NDA violation, though now I'm second-guessing that...

Re: You might want to stop running atop

#45
post #39

Earlier quoted context omitted.

It could also be any number of other things too, like it's severe enough that the author feels its responsible to wait for mitigation efforts before disclosing anything about the issue that could lead to it being exploited.

The existence and phrasing of this post implies that the author doesn't trust the atop developers to fix anything in a timely manner if at all.

The developers don't necessarily have to be the ones working on mitigation efforts.

Re: You might want to stop running atop

#47
post #35

Earlier quoted context omitted.

This. Not only that, I don't know of a single person (IRL or online) who used atop, like, ever. In fact, this is the first time I'm even hearing of atop. IIRC, most folks went from top -> htop -> glances -> various btop variants (bashtop, bpytop, btop++ etc)

Btop variants, glances, why should I move from htop?

I’d summarize btop++ as: a much richer and more flexible experience with a very pleasing UI.

Screenshots summarize this better than I can [0].

- [0] https://github.com/aristocratos/btop?tab=readme-ov-file#scre...

Re: You might want to stop running atop

#48
post #28

I’m actually surprised I didn’t have it installed, what with all the packages I check out just through sheer curiosity. Thanks Rachel! I’ll avoid it in the future.

Alarmingly, I had it installed on my home server, for some odd reason. I don't remember ever using it.

For the purposes listed on the tin (as it were), it can be a useful forensic tool in the absence of other monitoring
Post reply on HN