Settings

Theme

"Security problems are just bugs" (2017)

lkml.org

2 points by guiambros 2 days ago · 1 comment

Reader

guiambrosOP 2 days ago

Posting this to remind folks of Linus' and the kernel team's longstanding stance on security vulnerabilities, given the recent CopyFail discussion [1].

The researchers followed the standard disclosure process of 90+30, but distros were not notified. The kernel had a bug, but kernel developers did not (and will not) notify downstream distros.

The real discussion we should be having is: what should be the responsible disclosure process, and who should be accountable for contacting the downstream projects?

And should the Linux kernel be treated differently than other opensource projects? And if yes, where do we draw the line? If, for example, I find a bug in OpenSSL, is it reasonable to expect that I contact every single operating system, device maker, or library developer that packages openssl in their gizmos?

[1] https://news.ycombinator.com/item?id=47965108

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection