Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

441–450 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#441

Earlier quoted context omitted.

Just as a purely intellectual exercise, what changes about this if we leave aside ideas of "owe," "deserve ," and "earn?" There's not really an enforcement mechanism in FOSS like there is in capitalism world, it just comes down to what we want our part of the world to look like. So I think we'd think more clearly if we leave aside the ideas like "who owes who what." I think it's fun to imagine what sort of motivation…

"leave aside ideas of "owe," "deserve ," and "earn?"" Nonsensical string of words with no meaning. If you want something that someone else isn't giving you, you have the option to try to do it yourself, or try to compel someone else to give you what you want somehow. Feel free to idk pay someone to track the kernel list and 4000 others and send you heads-ups? Try to pass a law to make people do what you want since yo…

> If you want something that someone else isn't giving you, you have the option to try to do it yourself, or try to compel someone else to give you what you want somehow.

Yes, exactly, the opposite of paying, since when you pay someone something they owe you whatever you paid for.

If we leave aside owe, deserve, and earn, we can start discussing things like what we want our kernel ecosystem to look like, how we can make it safer, etc, without being burdened by these concepts.

It's a simple intellectual exercise, that's all. If you're having a strong reaction to it, imo that'd make it even more fun for you to participate.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#443

Earlier quoted context omitted.

There is no such thing as "the responsible disclosure protocol". There's really no such thing as "responsible disclosure" at all, but "the responsible disclosure protocol" is a term I have literally never heard before. (I've been a vulnerability researcher since the mid-1990s, for what it's worth.)

https://en.wikipedia.org/wiki/Coordinated_vulnerability_disc... > In computer security, coordinated vulnerability disclosure (CVD, sometimes known as responsible disclosure) I guess you can learn something new after 36 years. If you are referring to what you quoted, your pedantry and sharpshooting would result in an incomplete English sentence: "that's why we have the responsible disclosure" is missing a noun. Now th…

What rules were not followed here?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#444

Earlier quoted context omitted.

Microsoft has a long and sordid history of cheerfully doing anything they can to fuck everyone over just to make a few more percentage points of profit. Linux is a free kernel that literally revolutionized the computing landscape.

Yes, this is the sacred cow status being referred to.

"You keep using that word..." or term in this case.

There are only 2 words in this term, and neither one even slightly applies.

A sacred cow is called a sacred cow because there is no reason for it to be sacred.

Linux is perfectly subject to criticism, and so not at all sacred.

Linux has earned a stunning amount of respect and gratitude by actually providing stunning utility and quality. IE, it's not just a random object like a cow that everyone decided to worship for no reason.

Spoken as a freebsd user who has plenty of critiques of the entire linux ecosystem.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#445

Earlier quoted context omitted.

"leave aside ideas of "owe," "deserve ," and "earn?"" Nonsensical string of words with no meaning. If you want something that someone else isn't giving you, you have the option to try to do it yourself, or try to compel someone else to give you what you want somehow. Feel free to idk pay someone to track the kernel list and 4000 others and send you heads-ups? Try to pass a law to make people do what you want since yo…

> If you want something that someone else isn't giving you, you have the option to try to do it yourself, or try to compel someone else to give you what you want somehow. Yes, exactly, the opposite of paying, since when you pay someone something they owe you whatever you paid for. If we leave aside owe, deserve, and earn, we can start discussing things like what we want our kernel ecosystem to look like, how we can m…

But there was no intellectual excercise. Only a complaint with no proposal.

You want someone to do something for you for some other reason than that they owe you.

They already are doing something for you that they don't owe you. They are writing software that you benefit from. You just want them (or somebody) to do something else that they don't owe you.

They aren't, because they don't owe you and it's not something they want to do for fun, and so since the problem is they don't owe you, you wish to set aside words like "owe".

Well sure. Looks like you found the problem and the solution alright. Why didn't anyone else think of that?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#446
post #425
post #412

Interesting comment by Greg Kroah-Hartman when asked why the kernel team doesn't notify distros directly > Nope, sorry, we are NOT allowed to notify anyone about anything "ahead of time" otherwise we will have to tell everyone about everything. That's the only policy by which all the legal/governmental agencies have agreed to allow us to operate in, so we are stuck with it. I'd be interested in knowing more about tha…

The members of the kernel security team are not allowed to tell their employers anything that happens on the security list. They are there as individual members, not as employees. And try to define "major distros" in a way that actually means anything viable. If you just want to count users, then that would only be Android (everything else is a rounding error.) After Android, that would be Yocto, and then Debian. All…

If you want to talk about possible exploiting being done. Then Android is out (userland is crippled) and I guess yocto as well (same issue). Not that they can’t be attacked, but because mostly what is there is static. As it’s a privilege escalation attack, that leaves us with anything that is running code by unverified users (vulnerable server software, linux shell services, untrusted software you think you’ve sandboxed with user account,…). That put Debian, Ubuntu, Rhel, Fedora, Arch,… installation as the juicest targets.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#447

Earlier quoted context omitted.

Yes, this is the sacred cow status being referred to.

"You keep using that word..." or term in this case. There are only 2 words in this term, and neither one even slightly applies. A sacred cow is called a sacred cow because there is no reason for it to be sacred. Linux is perfectly subject to criticism, and so not at all sacred. Linux has earned a stunning amount of respect and gratitude by actually providing stunning utility and quality. IE, it's not just a random ob…

> Linux has earned a stunning amount of respect and gratitude by actually providing stunning utility and quality. IE, it's not just a random object like a cow that everyone decided to worship for no reason.

I agree.

> A sacred cow is called a sacred cow because there is no reason for it to be sacred.

Here we diverge. Linux earns sacred cow status when people interpret legitimate criticism of it as an attack that must be debunked or dismissed. And there's plenty of that happening in this forum; you may not be treating it as a sacred cow, but plenty of people are.

And to expound on why it even matters, it does a disservice to Linux to treat it this way: if you can't engage with its flaws, you'll never help fix them, and instead attack people who try.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#448

Earlier quoted context omitted.

> If you want something that someone else isn't giving you, you have the option to try to do it yourself, or try to compel someone else to give you what you want somehow. Yes, exactly, the opposite of paying, since when you pay someone something they owe you whatever you paid for. If we leave aside owe, deserve, and earn, we can start discussing things like what we want our kernel ecosystem to look like, how we can m…

But there was no intellectual excercise. Only a complaint with no proposal. You want someone to do something for you for some other reason than that they owe you. They already are doing something for you that they don't owe you. They are writing software that you benefit from. You just want them (or somebody) to do something else that they don't owe you. They aren't, because they don't owe you and it's not something…

I don't feel like I'm complaining, I feel like I'm asking how else someone would frame it without leaning on the concepts mentioned. What changes about the dynamic then?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#449

Earlier quoted context omitted.

> the reporter should not be the one responsible for reporting separately to every single downstream of the thing they found a vuln in. Not "separately to every single downstream", there is the "linux-distros" mailing list for disclosures: https://oss-security.openwall.org/wiki/mailing-lists/distros This random blogpost from 2022 serves as a proof that disclosing kernel vulnerabilities to the distros list is a well-k…

It is literally not the vulnerability researcher's problem to solve or address this.

That is just being pedantic. Why did they absolutely need to release this into the wild now? Why couldn’t they have waited?

“30 days should be enough time” why? Why is 30 days a magic number? Especially in open source.

Yeah it isn’t the researchers problem to tell every distributor of the kernel about the fix or verify that everyone has the fix, but fuck maybe wait until at least someone has the fix and maybe don’t drop it on a Friday. That is just malicious

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#450

Earlier quoted context omitted.

But there was no intellectual excercise. Only a complaint with no proposal. You want someone to do something for you for some other reason than that they owe you. They already are doing something for you that they don't owe you. They are writing software that you benefit from. You just want them (or somebody) to do something else that they don't owe you. They aren't, because they don't owe you and it's not something…

I don't feel like I'm complaining, I feel like I'm asking how else someone would frame it without leaning on the concepts mentioned. What changes about the dynamic then?

But what does that mean? "owe" is just shorthand for the concept of obligation. For someone to do something, they need a reason to do it. It doesn't have to be a transaction but there does need to be some reason.

If no one is doing a task you want done because they aren't obligated to, then you seek some other reason besides obligation. Ok, what then?

Do you imagine say a dating website where people compete to look attractive by getting points by doing the best job at finding the most bugs and patches and reporting them to the most downstream consumers the fastest?

Post reply on HN