Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. so i woke up this morning to like 5 pages of scroll from a thread i was lucky enough to be included on here, with several kernel developers talking about the disclosure and coordination of the copyfail bug.

so i woke up this morning to like 5 pages of scroll from a thread i was lucky enough to be included on here, with several kernel developers talking about the disclosure and coordination of the copyfail bug.

Scheduled Pinned Locked Moved Uncategorized
7 Posts 5 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.socialV This user is from outside of this forum
    viss@mastodon.social
    wrote last edited by
    #1

    so i woke up this morning to like 5 pages of scroll from a thread i was lucky enough to be included on here, with several kernel developers talking about the disclosure and coordination of the copyfail bug.

    ive learned a lot about the mechanics of how the linux kernel devs work with the various linux distros.

    the short version is:
    when the kernel devs do stuff, it doesnt obligate the distros to. and almost everyone is a volunteer.

    viss@mastodon.socialV nosirrahsec@infosec.exchangeN 2 Replies Last reply
    0
    • viss@mastodon.socialV viss@mastodon.social

      so i woke up this morning to like 5 pages of scroll from a thread i was lucky enough to be included on here, with several kernel developers talking about the disclosure and coordination of the copyfail bug.

      ive learned a lot about the mechanics of how the linux kernel devs work with the various linux distros.

      the short version is:
      when the kernel devs do stuff, it doesnt obligate the distros to. and almost everyone is a volunteer.

      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.socialV This user is from outside of this forum
      viss@mastodon.social
      wrote last edited by
      #2

      the same day the bug was made public, i posted a little bit about it, and included a post on how to mitigate it on ubuntu hosts.

      it seems like the strongest foot forwards for security leaders, and folks who are hands-on-keyboard to mitigate this sort of stuff is to more or less do what everyone else has so far - do the tiny manual fix for now, then wait for the official one to seep through the layercake of plumbing into the kernel of whatver you run

      viss@mastodon.socialV 1 Reply Last reply
      0
      • viss@mastodon.socialV viss@mastodon.social

        the same day the bug was made public, i posted a little bit about it, and included a post on how to mitigate it on ubuntu hosts.

        it seems like the strongest foot forwards for security leaders, and folks who are hands-on-keyboard to mitigate this sort of stuff is to more or less do what everyone else has so far - do the tiny manual fix for now, then wait for the official one to seep through the layercake of plumbing into the kernel of whatver you run

        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.socialV This user is from outside of this forum
        viss@mastodon.social
        wrote last edited by
        #3

        i appreciate this approach because it forces people who make decisions to at least be knowledgeable enough about the shit that they run, the shit that is in their perview, to be functionally useful.

        there is this mba-flavored school of thought that managers dont have to be technical, and never need to get into the weeds or 'the technicals' about the systems their teams manage and the day to day of it all.

        this bug is a great example of why that school of thought is fucking stupid.

        nf3xn@mastodon.socialN 1 Reply Last reply
        0
        • viss@mastodon.socialV viss@mastodon.social

          i appreciate this approach because it forces people who make decisions to at least be knowledgeable enough about the shit that they run, the shit that is in their perview, to be functionally useful.

          there is this mba-flavored school of thought that managers dont have to be technical, and never need to get into the weeds or 'the technicals' about the systems their teams manage and the day to day of it all.

          this bug is a great example of why that school of thought is fucking stupid.

          nf3xn@mastodon.socialN This user is from outside of this forum
          nf3xn@mastodon.socialN This user is from outside of this forum
          nf3xn@mastodon.social
          wrote last edited by
          #4

          @Viss and something to be grateful for is that we have a mitigation within a day of the announcement, great messaging, @mttaggart demo and its fixed, we're done. Great teamwork everybody. As it should be.

          Meanwhile very similar series of bugs, same severity imho is still unpatched on Windows a month after the unhinged researcher dropped them. Yeah you're just screwed.

          bhhaskin@social.bitsofsimplicity.comB 1 Reply Last reply
          0
          • viss@mastodon.socialV viss@mastodon.social

            so i woke up this morning to like 5 pages of scroll from a thread i was lucky enough to be included on here, with several kernel developers talking about the disclosure and coordination of the copyfail bug.

            ive learned a lot about the mechanics of how the linux kernel devs work with the various linux distros.

            the short version is:
            when the kernel devs do stuff, it doesnt obligate the distros to. and almost everyone is a volunteer.

            nosirrahsec@infosec.exchangeN This user is from outside of this forum
            nosirrahsec@infosec.exchangeN This user is from outside of this forum
            nosirrahsec@infosec.exchange
            wrote last edited by
            #5

            @Viss yeah, I'm turning 42 and I just learned more about how the ecosystem does shit than I ever have in one sweep.

            1 Reply Last reply
            0
            • nf3xn@mastodon.socialN nf3xn@mastodon.social

              @Viss and something to be grateful for is that we have a mitigation within a day of the announcement, great messaging, @mttaggart demo and its fixed, we're done. Great teamwork everybody. As it should be.

              Meanwhile very similar series of bugs, same severity imho is still unpatched on Windows a month after the unhinged researcher dropped them. Yeah you're just screwed.

              bhhaskin@social.bitsofsimplicity.comB This user is from outside of this forum
              bhhaskin@social.bitsofsimplicity.comB This user is from outside of this forum
              bhhaskin@social.bitsofsimplicity.com
              wrote last edited by
              #6

              @nf3xn @Viss @mttaggart wasn't there mitigation in the announcement itself? Disable the module. AF_ALG isn't really used in most systems.

              cmars@infosec.exchangeC 1 Reply Last reply
              0
              • bhhaskin@social.bitsofsimplicity.comB bhhaskin@social.bitsofsimplicity.com

                @nf3xn @Viss @mttaggart wasn't there mitigation in the announcement itself? Disable the module. AF_ALG isn't really used in most systems.

                cmars@infosec.exchangeC This user is from outside of this forum
                cmars@infosec.exchangeC This user is from outside of this forum
                cmars@infosec.exchange
                wrote last edited by
                #7

                @bhhaskin @nf3xn @Viss @mttaggart If your distro ships a kernel that allows it. #coreos and #fedora compile it as builtin and you can't unload it

                I wonder how many other "cloud native" distros are in this situation?

                1 Reply Last reply
                1
                0
                • R relay@relay.infosec.exchange shared this topic
                Reply
                • Reply as topic
                Log in to reply
                • Oldest to Newest
                • Newest to Oldest
                • Most Votes


                • Login

                • Login or register to search.
                • First post
                  Last post
                0
                • Categories
                • Recent
                • Tags
                • Popular
                • World
                • Users
                • Groups