4 ms·
It really pisses me off that responsible disclosure timelines are being ignored.
by cbarnes99 5mo ago
It really pisses me off that responsible disclosure timelines are being ignored.
- roxolotl 5mo agoThe dirty frag repo says: > Because the responsible disclosure schedule and the embargo have been broken, no patch exists for any distribution. I had to do a double take reading that. It’s written something happened and prevented them from following a schedule but seemingly they chose to release the information. I hope I’m missing something where it was forcibly disclosed elsewhere. Edit: Moments later I refreshed the homepage and saw the announcement. They do claim to have consulted with maintainers
- rafram 5mo ago> Due to external factors, the embargo has been broken, so no patch exists for any distribution. Very odd wording. I assume there’s an interesting/upsetting story here that will come out soon.
- tom_ 5mo agoPresumably: * https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md#disclosure-timeline https://github.com/V4bel/dirtyfrag/blob/master/assets/write-... * https://github.com/V4bel/dirtyfrag/blob/master/assets/write-up.md#disclosure-timeline-1 https://github.com/V4bel/dirtyfrag/blob/master/assets/write-...
- bellowsgulch 5mo agoif you don't already consider responsible disclosure a quaint idea, you may want to grow warm on it the idea that it exists at all is more or less a gentleman's agreement in the engineering world anyway
- Root_Denied 5mo agoLess a gentleman's agreement and more of a question of economic incentives going away. Companies aren't paying out bounties at the rates they used to (possibly because they've realized there's little financial incentive to do so for most findings) and simultaneously they're being inundated with AI slop findings that somehow have to still be triaged and evaluated.
- hluska 5mo ago[flagged]
- irishcoffee 5mo agoYeah, it isn’t an LLM. Missed 2 capitalizations and 2 periods, there is however a comma. Btw, s/onto/on to Onto can be synonymously replaced with “on top of” which doesn’t work in that sentence. It’s much more interesting to pay attention to the spirit of the comment than the structure, which I believe is also in the site guidelines. I’m also confident I have multiple grammatical errors in this comment.
- ahpeeyem 5mo agobut there is punctuation: there's one comma and two apostrophes! everything we need to comprehend, nothing more correctly using those tells me it was a stylistic choice not to use capital letters and omit the periods. fwiw the HN guidelines say more about not posting "shallow dismissals", not complaining about "tangential annoyances" and being "kind, not snarky" than about grammar and punctuation: https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- deleted 5mo ago[deleted]
- creatonez 5mo agoIn this case, no insiders broke the embargo. It was reverse engineered from the patch by an unrelated third party and a proof of concept immediately came out of it. At that point, it's kinda fair game.
- vintermann 5mo agoI assume that while Mythos may be really good at finding vulnerabilities, lighter models may still do a pretty good job of explaining/exploiting the vulnerability if given the patch which fixes it.
- mattstir 5mo agoMaintainers attempt to reduce the likelihood of that somewhat by giving security patches boring-sounding commit messages. When there are thousands of patches for every kernel release to sift through, that adds a small barrier for would-be exploiters.
- CodesInChaos 5mo agoAren't patches usually covered by the embargo as well, and kept private until the deadline?
- creatonez 5mo agoFor proprietary software, sure. But open source projects rarely ever work like this. Especially for a project like the kernel, there's no reasonable way to decide who out of thousands of interested parties should have access first. Android is a rare exception, as of a few years ago they started a program where phone manufacturers get very favorable early access to AOSP code 4 months ahead of public release.
- zmj 5mo agoIf the fix commit is public, so is the issue being fixed.
- jeroenhd 5mo agoWith copy.fail the security patch wasn't listed as such so there wasn't a lot of attention on the issue as it remained dormant in most kernels for a while. I don't doubt that the patch reversal + exploit PoC made by a third party is the result of people figuring out how patches work in open source projects like these. Anyone with access to a good enough LLM can scour through supposedly minor bug fixes that might hide a critical vulnerability rather than doing it all manually. The LLM will probably throw up tons of false positives and miss half the issues, it you only need one or two successes.