4 ms·
Have big security vulnerabilities been cropping up more often recently or does it seem that way because I've started to pay attention?
by Oculus 12y ago
Have big security vulnerabilities been cropping up more often recently or does it seem that way because I've started to pay attention?
- drzaiusapelord 12y agoIts been a bad time for FOSS/Linux systems. Heartbleed, the occasional priv escalation, apt-get, bash, etc. Or whatever the hell happened at TrueCrypt. Or the recent AOSP browser bug in Android that probably won't be patched by any OEM/Carrier. These are all pretty serious issues. Not to mention the endless wave of malware targeting Windows systems, especially the evil cryptolocker ransomware. I really do think heartbleed was a wake-up call for some people and a lot of extra auditing is being done, perhaps with some healthy paranoia fueled by the recent NSA allegations. Software, in general, imo, is pretty insecure. The exploits, bugs, etc are out there and if you'll find them if you look hard enough. Considering software is always being updated, that also means news bugs and security issues. As a sysadmin, I've just seen too often how the sausage is made. I have zero illusions about security. There are just too many avenues to compromise, be it via software or via plain-jane social engineering. I think one day in the future we (or our children) are going to look back at the age of viruses and buffer overflows and wonder how the hell we managed to get by, the same way I look at cars from the 50s-60s that suffered from things like vapor lock, were incredibly unsafe, and other issues that really don't exist today.
- lonnyk 12y agoAre you referring to this apt-get vulnerability or another one: https://lists.debian.org/debian-security-announce/2014/msg00219.html https://lists.debian.org/debian-security-announce/2014/msg00... ?
- dpeck 12y agoyou're just paying attention. There have been some interesting ones the last year or two but this is really a trickle compared to early through mid 2000s
- fromtheoutside 12y agoI still remember Redhat 6.2. Most remote exploits in a distribution ever.
- hijinks 12y agohttp://www.cvedetails.com/browse-by-date.php http://www.cvedetails.com/browse-by-date.php Its not like each year is an increase.. but it seems this year has had more major giant remote ones then in the past
- zobzu 12y agopeople started to pay attention. theres a bunch of new vulns being patched daily. if you follow cve's or oss list you can see that. what's "new" (been done for a few years now) is that there's more marketing drive behind them. Fancy commercial names and websites dedicated and issues are often exaggerated. Actually super critical vulns are still rare (like HB, codered, etc.)