31 ms·
So what do you propose is the alternative? Not tell you about the vulnerability at all until a patch is released? Publish all the details about the vulnerabilit
by iamtedd 4y ago
So what do you propose is the alternative? Not tell you about the vulnerability at all until a patch is released? Publish all the details about the vulnerability before a patch is available?
Seriously, what are you complaining about?
- rascul 4y agoI just want actionable information is all. If I have to wait a couple days, fine. Giving me vague information I can't do anything with is useless.
- iamtedd 4y ago> I just want actionable information Which is, according to TFA, being released on 1 Nov., and according to my calendar, is in 3 days... Problem solved?
- rascul 4y agoI'm not yet convinced there's a problem.
- iamtedd 4y agoYou're not convinced? About a security vulnerability... From an open-source project... That has a history of major security vulnerabilities... Because there's no detailed information yet... When industry best practice is to not give detailed information without a patch or workaround... And they're giving you a heads-up for required mitigation in three days... Rather than right now...
- rascul 4y agoNo, I'm not convinced that the vulnerability is something I need to care about, because there's no details about it. I can make that determination when I have details. I am well aware of that project's history. I see no information given that would imply this to be anything more special than a regular update for me, for which the process I have already streamlined. I understand the practice of not giving the details until there's a patch and I'm OK with that, but there's now been over 10 submissions to HN about it with over 150 combined comments and all we know is that an update is coming. I'm not buying into the hype.
- sodality2 4y agoTo provide a counter, it's the second total vuln to be labeled critical by OpenSSL - first was in 2014, and it was Heartbleed...
- detaro 4y ago"be prepared to update affected systems at $point_in_time" seems actionable to me. You for some reason thinking that such a warning doesn't warrant taking the recommended action doesn't mean it isn't actionable, it means you choose to ignore it.
- rascul 4y agoAn update is nothing special that I have to be prepared for. I do it all the time across all my systems, and it's largely automated. If a single update is such a burden that you must prepare days in advance for then perhaps there's room to improve the processes.
- stoplying1 4y ago"I'm good at DevOps and everyone else should be too", feels tangential, and isn't going to help you when your banking session gets compromised because your bank wasn't prepared to roll this out through any expedited process versus their regulatory compliant, slow process. (As an example/thought experiment. I make no claims about the vulnerability at hand.)
- rascul 4y agoI don't know anything about the update processes banks use. I would hope they wouldn't have to jump through hoops to apply a security update. Didn't they learn this already?
- adamckay 4y agoWhat do you expect banks and other regulated industries do? YOLO patch whatever and whenever? I don't work in a regulated industry where it's required, but we do similar with a proper change control process and there's not a single individual that's authorised to perform changes without oversight, (even if that oversight from senior leadership comes retrospectively).
- 4y ago
- iso1631 4y agoI spent a few minutes checking my cmdb for openssl3, and have allocated 30 minutes on Tuesday to upgrade the few machines that have openssl3. When corporate infosec starts to panic, probably about Thursday based on the jndi issue, I'll be able to point them to our log which shows how it was handled.