5 ms·
Why does this need to be a whole ass website
by turkeyboi 4mo ago
Why does this need to be a whole ass website
- dragontamer 4mo agoWhat? Is there something in this website that feels unnecessary? It seems like a good format of sharing high quality information. This looks like a full bug into a complete root escalation of a kernel. That's hard to do and deserving of praise. The fact that we have a writeup organized like this is awesome. ------- This is sort of the expert level stuff that I thought HackerNews would most enjoy.
- cryo32 4mo agoYou're not going to get anywhere in the security sector unless you gain notoriety i.e. are noticed. This appears to come from dressing up like Elton John in a feather suit and hiring a marketing team.
- tptacek 4mo agoIt's a wall of text about a kernel stack overflow. I'm not sure where the "Elton John" part is. Is it... that they used an accent color?
- 866-RON-0-FEZ 4mo agoMaybe the researcher was wearing windshield-wiper spectacles when he discovered the vulnerability. I don't understand why you're being so defensive about this.
- tptacek 4mo agoBecause it's a tiresome, tropey, and ultimately invalid complaint. Look downthread at the person who said the FreeBSD commit log was better than this page, despite being inscrutable to security practitioners who don't work in the kernel and not saying a word about proven exploit vectors. These complaints aren't about what's better or worse for the user community; they're about people trying to put vulnerability researchers in their place.
- 866-RON-0-FEZ 4mo agoWhile I believe whimsical names will always be silly, I do concede that commit log is effectively useless to 99% of eyeballs.
- tptacek 4mo agoIt's not even a complete description of the vulnerability. It's what the kernel maintainers need to know to understand and fix the bug in the code. The claim that it's superior to the branded vulnerability page gives away the whole game.
- cryo32 4mo agoAs a member of the user community, I only care when it appears on the security list and then that it's patched. And I want to see that on the changelog. And that's about it. I don't want or need fanfare, marketing or any of that stuff. It's a bug for fucks sake. There will be people having web pages for Gnome user interface bugs next.
- GoblinSlayer 4mo agoBuffer overflow.
- tptacek 4mo agoWhy not? This weird complaint has been happening since ~2010 and it has never made any sense. You are strictly better off with the website than without it. When it was vulnerability researchers getting all peevish about the status competition they were running, I at least understood where the complaint was coming from, but even among practitioners, branded vulnerabilities are so much the norm at this point that there's no status implication anymore.
- themafia 4mo ago> You are strictly better off with the website than without it. Why? This is a better resource in every way: https://cgit.freebsd.org/src/commit/?id=000d5b52c19ff3858a6f0cbb405d47713c4267a4 https://cgit.freebsd.org/src/commit/?id=000d5b52c19ff3858a6f... It details the actual problem instead of showing off tired stack exploit tricks.
- tptacek 4mo agoNo, that commit log is obviously not better than the page explaining the vulnerability and the exploit vectors. Case in point: what's "tired" about the stack exploitation techniques they're using here? And, while you're not right, even stipulating that you were, what would that matter? How is anyone better off with less explanation of a vulnerability?
- themafia 4mo agoThe website explains an exploit. I've seen exploits before. The commit explains the unique issue. I'm more interested in the why than the how. I suppose people with different overall goals will see that differently.
- tptacek 4mo agoYou didn't answer my question. What's "tired" about the exploit technique here?
- tom_ 4mo ago
- rs_rs_rs_rs_rs 4mo agoHave you not done anything remotely interesting for you that you want to build a website so the whole world can see it?
- 866-RON-0-FEZ 4mo agoIt gives legitimacy to whatever whimsical name was given to a vulnerability by registering the domain. CVE numbers are for boring professionals.
- elkrapo 4mo agoThe cool kiddies wait and time their disclosures on the cool numbers.
- throwaway613746 4mo ago[dead]