Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. It is nice to see getting Linux more secure every day because it is developed in the open.

It is nice to see getting Linux more secure every day because it is developed in the open.

Scheduled Pinned Locked Moved Uncategorized
linuxsecuritycopyfail
8 Posts 3 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • lioh@social.anoxinon.deL This user is from outside of this forum
    lioh@social.anoxinon.deL This user is from outside of this forum
    lioh@social.anoxinon.de
    wrote last edited by
    #1

    It is nice to see getting Linux more secure every day because it is developed in the open. Just to remind any (AI) security researchers that the real reason for that was collaboration and helping each other. What happens now with Mythos & Co reminds me more of a person getting raped and then victem-blamed because they where wearing a mini-skirt.

    In the case of copyfail the researchers do not even give a f@%k about community and have verified only paid distributions.

    #linux #security #copyfail

    Link Preview Image
    lioh@social.anoxinon.deL marshray@infosec.exchangeM 2 Replies Last reply
    0
    • lioh@social.anoxinon.deL lioh@social.anoxinon.de

      It is nice to see getting Linux more secure every day because it is developed in the open. Just to remind any (AI) security researchers that the real reason for that was collaboration and helping each other. What happens now with Mythos & Co reminds me more of a person getting raped and then victem-blamed because they where wearing a mini-skirt.

      In the case of copyfail the researchers do not even give a f@%k about community and have verified only paid distributions.

      #linux #security #copyfail

      Link Preview Image
      lioh@social.anoxinon.deL This user is from outside of this forum
      lioh@social.anoxinon.deL This user is from outside of this forum
      lioh@social.anoxinon.de
      wrote last edited by
      #2

      It sadly sucks on so many levels. It is one of the worst releases I have seen so far. Even the informieren on how to mitigate the issue is unclear. Probably AI generated as well. What now? 'Patch now' or 'Before you can patch'? And no, I will not run your exploit code on my machine.

      #copyfail

      Link Preview Image
      0mega@sk.zehnvorne.social0 1 Reply Last reply
      0
      • lioh@social.anoxinon.deL lioh@social.anoxinon.de

        It is nice to see getting Linux more secure every day because it is developed in the open. Just to remind any (AI) security researchers that the real reason for that was collaboration and helping each other. What happens now with Mythos & Co reminds me more of a person getting raped and then victem-blamed because they where wearing a mini-skirt.

        In the case of copyfail the researchers do not even give a f@%k about community and have verified only paid distributions.

        #linux #security #copyfail

        Link Preview Image
        marshray@infosec.exchangeM This user is from outside of this forum
        marshray@infosec.exchangeM This user is from outside of this forum
        marshray@infosec.exchange
        wrote last edited by
        #3

        @Lioh They reported the bug to the Linux kernel security team over a month ago. A CVE was issued. I don’t know where the ball was dropped but, AFAICT, not a single distro took it seriously enough to release a patch.

        It’s not the bug reporter’s job to run a testing service for everyone (mostly large for-profit companies) downstream of the Linux kernel.

        lioh@social.anoxinon.deL 1 Reply Last reply
        0
        • marshray@infosec.exchangeM marshray@infosec.exchange

          @Lioh They reported the bug to the Linux kernel security team over a month ago. A CVE was issued. I don’t know where the ball was dropped but, AFAICT, not a single distro took it seriously enough to release a patch.

          It’s not the bug reporter’s job to run a testing service for everyone (mostly large for-profit companies) downstream of the Linux kernel.

          lioh@social.anoxinon.deL This user is from outside of this forum
          lioh@social.anoxinon.deL This user is from outside of this forum
          lioh@social.anoxinon.de
          wrote last edited by
          #4

          @marshray you can paint ot how you want. I just think it's not nice at all.

          marshray@infosec.exchangeM 1 Reply Last reply
          0
          • lioh@social.anoxinon.deL lioh@social.anoxinon.de

            @marshray you can paint ot how you want. I just think it's not nice at all.

            marshray@infosec.exchangeM This user is from outside of this forum
            marshray@infosec.exchangeM This user is from outside of this forum
            marshray@infosec.exchange
            wrote last edited by
            #5

            @Lioh Reporting security vulnerabilities is a worse-than-thankless job.

            lioh@social.anoxinon.deL 1 Reply Last reply
            0
            • marshray@infosec.exchangeM marshray@infosec.exchange

              @Lioh Reporting security vulnerabilities is a worse-than-thankless job.

              lioh@social.anoxinon.deL This user is from outside of this forum
              lioh@social.anoxinon.deL This user is from outside of this forum
              lioh@social.anoxinon.de
              wrote last edited by
              #6

              @marshray really depends HOW one does it.

              marshray@infosec.exchangeM 1 Reply Last reply
              0
              • lioh@social.anoxinon.deL lioh@social.anoxinon.de

                It sadly sucks on so many levels. It is one of the worst releases I have seen so far. Even the informieren on how to mitigate the issue is unclear. Probably AI generated as well. What now? 'Patch now' or 'Before you can patch'? And no, I will not run your exploit code on my machine.

                #copyfail

                Link Preview Image
                0mega@sk.zehnvorne.social0 This user is from outside of this forum
                0mega@sk.zehnvorne.social0 This user is from outside of this forum
                0mega@sk.zehnvorne.social
                wrote last edited by
                #7

                @Lioh@social.anoxinon.de Danke für die Einordnung, hatte gestern Abend leider nicht mehr genug Zeit mir das genauer anzuschauen ​​

                1 Reply Last reply
                0
                • lioh@social.anoxinon.deL lioh@social.anoxinon.de

                  @marshray really depends HOW one does it.

                  marshray@infosec.exchangeM This user is from outside of this forum
                  marshray@infosec.exchangeM This user is from outside of this forum
                  marshray@infosec.exchange
                  wrote last edited by
                  #8

                  @Lioh OK, so what’s your preferred vulnerability disclosure policy?

                  Just linking the document is fine.

                  1 Reply Last reply
                  1
                  0
                  • R relay@relay.infosec.exchange shared this topic
                  Reply
                  • Reply as topic
                  Log in to reply
                  • Oldest to Newest
                  • Newest to Oldest
                  • Most Votes


                  • Login

                  • Login or register to search.
                  • First post
                    Last post
                  0
                  • Categories
                  • Recent
                  • Tags
                  • Popular
                  • World
                  • Users
                  • Groups