5 ms·
> ksmbd is a new kernel module which implements the server side of the SMB3 protocol. […] The bigger goal is to add new features more rapidly […] which are easi
by brasetvik 5y ago
> ksmbd is a new kernel module which implements the server side of the SMB3 protocol. […] The bigger goal is to add new features more rapidly […] which are easier to develop on a smaller, more tightly optimized kernel server than for example in Samba.
That seems like a quite significant (external) attack surface to add to the kernel? (With plans on adding more)
- slownews45 5y agoNot directly related but aren't these the folks that are pulling out a lot of the insecure methods from the CIFS client? So that should be a good cleanup on that side. (ie, MD4?)
- rektide 5y agojust don't run/load the module then? i for one am super excited that i have a much lighter weight option available. for example, on my/my parents openwrt wifi routers to expose files with, in a way that other computers in the house can use. my fear of security holes is pretty weak. this will be exposed inside the firewall only (at least at first). and i trust that by promoting & moving such a thing into the kernel, we'll have a very involved active community trying to make sure things are safe. we'll notice & catch exploits quickly once they start to be used. the message here of fear & uncertainty does not resound with me. quite the opposite. sunlight is not perfect but it has proven to be a progressive & very adaptive means to disinfect & secure within cybersecurity. edit: wow, -2, some strong disagreement! not sure what ya'll are so afraid of!! why so conservative? doesn't this seem like progress?
- spijdar 5y agoWindows has a long and colorful history full of serious, remotely exploitable vulnerabilities made oh so much worse by the fact they're running inside kernel space. I'm sure there are plenty of people who don't like the idea of bringing this into Linux. FWIW, these exploits are not all in legacy code. A recent SMB3 vulnerability "SMBGhost" used a lack of bounds checking of compressed data in the new SMB3 compression code, which can be triggered pre-auth. If that bug is in a user space program, it's a bad bug, but you're at least not (unnecessarily!) opening up your entire kernel to RCE. Even assuming "many eyes find all bugs" some don't want to introduce the risk at all.