logoalt Hacker News

socializer • today at 2:27 AM • 3 replies • view on HN

It's not very interesting. Linus, and by extension the Linux kernel, long had a dismissive attitude toward security research. This is basically a childish swing from one extreme (nothing gets a CVE) to another (everything gets a CVE).

Kernel development is well-funded, both via grants and by direct employment at big tech companies, and if they wanted to properly triage and annotate vulnerabilities, and provide reasonable assessments of what is or isn't likely to be a security risk, they absolutely could. They almost certainly could go to Google and say "we need two people full-time on your payroll for this" and they would get it.

I don't want to dunk on them too much because they're generally doing God's work, but these absolutist security stances are not worth being taken seriously.

It's basically saying that they can't possibly provide a valuable service for 99.999% of the install base because there might a hypothetical person out there using Linux in a really weird way. If Microsoft tried to make an argument like that, they'd get crucified.


Replies

serbuvlad • today at 7:05 AM

I don't think that Linus is dismissive of security, it is that he is very much a proponent of always rolling to the latest stable release.

Linux only ever wanted to promise support for the latest release and even Linux LTS is a concession.

And CVEs are basically a useless concept if you roll. (or at least not any more useful than any other bug tracker which supports tags)

➕ show 1 reply
asdfaoeu • today at 3:06 AM

Let's say they do and only 5% are "security issues" you still need to update either way.

vlovich123 • today at 3:03 AM

The counterpoint is that by putting CVEs on bugs that are more easily exploitable provides a roadmap for attackers. Of course, in the current LLM age that's probably a moot point, but that could be the reason for this.