5 ms·
I don't care if Jesus, the director of security in heaven said that. I'm going to take a look at both arguments and decide for myself. No need to name drop.
by philtar 10y ago
I don't care if Jesus, the director of security in heaven said that.
I'm going to take a look at both arguments and decide for myself. No need to name drop.
- ben0x539 10y agoThe name (or title) drop might effect appropriate urgency, seems legit. Edit: Don't downvote people trying to help me improve my english. :(
- MrF3ynmann 10y agoaffect
- dzamo_norton 10y agoeffect
- isbadawi 10y agoEffect is correct here.
- chowells 10y agoBecause the other comment didn't spell it out: effect is correct there. Effect as a verb means something like "to cause to happen". Don't pretend effect/affect is just a noun/verb split. Both words have meanings as both verbs and nouns. It's best to just learn both meanings of each instead of following some rule that's wrong a fair amount of time.
- tyre 10y agoMary Norris, copy editor at the New Yorker, has a wonderful short video on this: http://www.newyorker.com/culture/culture-desk/comma-queen-affect-vs-effect http://www.newyorker.com/culture/culture-desk/comma-queen-af...
- monktastic1 10y agoI don't care if Jesus, director of grammar in heaven said this.... Just kidding.
- hogrammer 10y ago@dang -- please remove this parent comment. It's wrong.
- tedmiston 10y agoYour usage is actually correct. Which is great, considering many native English speakers get this one wrong. The heuristic we hear in school is something like "use 'affect' as a verb and 'effect' as a noun," which like many grammar heuristics is of course an oversimplification of reality. Usage of effect as a verb isn't super common in general conversation by native English speakers whereas I think most might choose to say something like "establish authority" instead in this case, but still your intention is still clear.
- therein 10y agoWho filled in for the position of Director of Security between 0 and ~32AD?
- geofft 10y agoI have no information here, but it's certainly possible that both sides are not willing to publicly disclose the full extent of the vulnerability. I think that's less wise than usual given what Red Hat is writing and how disputed it is, but that's probably their standard practice. Some of the comments from Red Hat previously implied that they thought the vulnerability could only be exploited via ptrace, which SELinux denied by default for Docker containers. That's definitely not true; ptrace was used in the PoC because it's easy and likely to win the race condition, but you can also grab file descriptors out of /proc/$pid/fd. However, the blog post appears to show SELinux stopping attacks that don't involve ptrace, because SELinux forbids writing to an open file or an open network socket that has the wrong context. If Docker believes there are attack vectors that aren't covered by the default SELinux policies (such as writing to something that's not a regular file or network socket), they might be unwilling to disclose that too loudly until Red Hat gets around to saying "Uh, actually please patch".
- hoorayimhelping 10y ago>No need to name drop. Give it a rest. This is a semi-anonymous forum where people's identities aren't tied to their usernames. This isn't name dropping, it's providing helpful context.
- threeseed 10y agoWhat on earth is wrong with you ? This is a security incident. It's relevant and vital to know the background of people who are making statements like this. And sorry but not everyone is a kernel engineer who can navigate the truth between RedHat and Docker.