4 ms·
I found the reaction to this surprising. When Security Researcher tell a company about a bug they've found, and the company reacts badly, this community is usu
by feral 5y ago
I found the reaction to this surprising.
When Security Researcher tell a company about a bug they've found, and the company reacts badly, this community is usually strongly in favor of the Security Researcher.
The overworked corporate sysadmins don't get a lot of empathy. The assumption seems to be that that their software shouldn't have been vulnerable in the first place.
Now here's a security researcher researching smuggling bugs into the Linux kernel. It probably should be secure, and probably should face scrutiny. People have tried snuggle bugs into it before.[0]
So why is the opinion so strongly against the Security Researcher here?
What's the big difference in principal?
[0] https://freedom-to-tinker.com/2013/10/09/the-linux-backdoor-attempt-of-2003/ https://freedom-to-tinker.com/2013/10/09/the-linux-backdoor-...
- kstrauser 5y agoMy opinion: security researchers attack an organization’s products, like their code or website or services. UMN attacked the organization’s people to test their defenses. Lots of companies run bug bounty programs and thank you for finding vulnerabilities in their product. Humans don’t scale so well, though, and if you pester the hell out of a company’s office manager trying to social engineer them, that company is going to be super freaking annoyed at you. If UMN had analyzed the Linux code to find problems, then patched them, the kernel team would be happy. They didn’t. They spammed the human maintainers with a flood of patches and lied about why they were sending them. They conducted an impromptu and unanticipated phishing test, and you just don’t do that.
- hyper_reality 5y agoOne big difference is explained in the article. The fact that code going into the kernel is not as secure as we might hope is already known to the open source community. Maintainers are overworked and none would be surprised if you told them that it would be possible to smuggle in backdoors. This is not a "bug", but an issue with time and resources, and because the researchers attempted to add bugs to demonstrate it just makes it worse. On the other hand, security researchers are finding vulnerabilities that weren't previously known. They've discovered specific exploitable bugs, rather than introducing new ones. Following disclosure, the company can patch the vulnerabilities and users will be safer. Which makes that a laudable thing to do.
- wolverine876 5y agoThe difference is that HN likes Linux (and Elon Musk and etc.), and dislikes some others. If this happened with Google, for example, HN comments would say 'What are you complaining about? Review your patches! If you had done your job, it wouldn't have been a problem. The researchers did you and us a valuable service.' Critical thought, especially about ourselves, seems a victim of recent social trends.