Live data from Hacker News

For Linux kernel vulnerabilities, there is no heads-up to distributions

openwall.com

61–70 of 578 posts

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#61
post #42

Earlier quoted context omitted.

> maybe even criminal What’s your theory here? What crime?

If it's not a crime I see no reason not to work with partner nations to build responsible disclosure into a legal framework everywhere because it pretty obviously should be.

If you wanted to somehow make coordinated disclosure into a legal framework, that would be an interesting and complex project.

But it’s not the law anywhere I’m aware of today, and I’d not support it becoming a law.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#62

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

Counterpoint. End users have a right to mitigate this issue on their systems. It is a really really bad look for Linux, puts a bit of water on all hype around switching from Windows.

As opposed to all other operating systems with no CVEs ever?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#63

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

Counterpoint. End users have a right to mitigate this issue on their systems. It is a really really bad look for Linux, puts a bit of water on all hype around switching from Windows.

Hype around switching from Windows servers?

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#64
post #32

Earlier quoted context omitted.

Your advertising for them on HN would help them too, I bet.

Does it? Now that I see their name again in this context they're blacklisted for life.

Yes, exactly. Name and shame.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#65

Earlier quoted context omitted.

“Made it into the wild?” Patches landed a month ago. Should they also wait until my linksys router from 2018 has a patch ready?

It's a local vulnerability at least. How many people do you let log in to your router? With the way linux is used these days, I'd guess the number of systems with untrusted local users is pretty limited. Even with shared hosting, you generally have root in your VM or container anyway. Unless this enables an escape from that? Still the risk that people who run "curl | bash" without care could get bitten, but usually i…

Local root is part of the path to escaping

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#66
post #32

Earlier quoted context omitted.

Your advertising for them on HN would help them too, I bet.

Does it? Now that I see their name again in this context they're blacklisted for life.

Same. I did not know who they were, but now they have been named and shamed. Not every publicity is good.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#67
post #58

Earlier quoted context omitted.

and its your opinion that it doesn't. Shall we continue stating the obvious? We are communicating using glyphs. This language is English. We are on Hacker News. This branch of the conversation is extremely unproductive.

I asked a question and you replied with a statement. Your statement didn’t frame itself as an opinion but as fact. The hilarious bit is that the idea that they needed to coordinate is clearly broken even in just this example. They did give prior notice to the Linux developers, who issued a patch. And they’re still getting raked over the coals in this comment page by armchair quarterbacks who have decided they needed…

you seemed to suggest with your initial statement that any disclosure was acceptable as people would have been using the exploit prior to the disclosure. I don't think that's a strong argument given now the initial people who were using the exploit prior to disclosure are now joined by people who have learned of the exploit as a consequence of the disclosure happening before all the distribtions were ready.

So I feel like the argument reduces into "why is it a problem that now anyone could exploit it, if some people were exploiting it already". Which imho isn't a sensible argument because the issue is clearly the amount of people capable of using the exploit for nefarious purposes, which has increased.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#68
post #32

Earlier quoted context omitted.

Your advertising for them on HN would help them too, I bet.

Does it? Now that I see their name again in this context they're blacklisted for life.

Researchers are under no obligation to engage in coordinated disclosure and are free to sell 0day for profit. Just fyi. Be glad it was disclosed at all. Be glad a patch was available prior to release.

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#69

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

>> Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix.

Maybe a decade of corporations with revenue in the billions, paying peanuts and coffee money, for critical vulnerability disclosures made it....

Re: For Linux kernel vulnerabilities, there is no heads-up to distributions

#70
post #4

For context, the author of the linked post, Sam James, is a Gentoo developer. Anyway, this is a disaster. It was extremely irresponsible to share the exploit with the world before the distributions shipped the fix. Who knows how many shared hosting providers were hacked with this. It's also worrying that it seems there's no communication between the kernel security team and distribution maintainers. One would hope th…

Expecting people to do the right thing is a fundamental issue here. Why would you ever expect for all of vulnerabilities to be disclosed privately? There's very little actual incentive to do this. I'm honestly unaware of what systems could be put in place to prevent this but expecting people to always do the right thing is fantasy level thinking. I mean I bet the disclosers thought they were doing the right thing, he…

> expecting people to always do the right thing is fantasy level thinking.

Most people in tech think like the techie in this comic strip.

https://xkcd.com/538/

Post reply on HN