logoalt Hacker News

shimmanyesterday at 6:03 PM6 repliesview on HN

Expecting people to do the right thing is a fundamental issue here. Why would you ever expect for all of vulnerabilities to be disclosed privately? There's very little actual incentive to do this.

I'm honestly unaware of what systems could be put in place to prevent this but expecting people to always do the right thing is fantasy level thinking. I mean I bet the disclosers thought they were doing the right thing, hence why it's a bad thing to rely on.

edit: spelling/grammer.


Replies

dwedgeyesterday at 6:20 PM

When the exploit is an advertisement for an exploit detection company, not doing the right thing is a bad look

show 1 reply
egonschieleyesterday at 6:34 PM

Why don't all these distro maintainers add their own back doors, and mine crypto off our machines without our knowledge? Surely, there is some legal fine print they can add that would let them do that. There is very little incentive for them to maintain these systems, given how thankless and underpaid the work is.

holowoodmanyesterday at 6:10 PM

I can accept (and welcome) disclosure before there are patches.

But publishing a working exploit together with the disclosure before patches are available is really really irresponsible, maybe even criminal.

And no, the proposed mitigations don't help with half of the distributions out there...

show 5 replies
baggy_troughyesterday at 6:05 PM

Why wouldn't the linux security team notify the main linux distributions?

show 5 replies
skywhopperyesterday at 6:11 PM

I think it’s reasonable to expect folks in the security community who go to the trouble of creating a website detailing security vulnerabilities in specific listed software to pre-notify the security teams of that software. The CopyFail website calls out Ubuntu and Red Hat specifically, but apparently the author of the site did not inform them of the issue?

But even if you think making unethical decisions in personal self interest is something no one should be criticized for, surely the Linux kernel team ought to have some process for notifying the top distributions of an upcoming LPE, just out of practicality.

show 1 reply
bossyTeacheryesterday at 7:04 PM

> expecting people to always do the right thing is fantasy level thinking.

Most people in tech think like the techie in this comic strip.

https://xkcd.com/538/