[HN Gopher] Google Limiting IO_uring Use Due to Security Vulnera...
___________________________________________________________________
Google Limiting IO_uring Use Due to Security Vulnerabilities
Author : LinuxBender
Score : 14 points
Date : 2023-06-17 21:28 UTC (1 hours ago)
(HTM) web link (www.phoronix.com)
(TXT) w3m dump (www.phoronix.com)
| djbusby wrote:
| Some of the criticism starts with "security was an after
| thought". I first heard that line of criticism in 1999 about
| completely unrelated code. Yet, in 2020, the wizards of the
| Kernel make the same "mistakes" I was making 20+ years ago? (IMO,
| no chance).
|
| Engineers learn from mistakes...how is this industry not? Or, is
| "security after thought" just a lazy jab when any security issue
| is discovered? Or do we all still get so excited about the new-
| new that we keep skipping this part with the "it should be easy
| to fix later" BS we tell ourselves (about nearly everything)?
| paddw wrote:
| Security is often implementation dependent, meaning: you need
| to understand exactly how your software does what it does
| before you can understand how to do that securely.
|
| For non-trivial software, this almost always means you will
| have to build an implementation first, before thinking about
| how to add security.
|
| Overall, I think security has gotten much better, but for
| complex software there are always going to be challenges.
| arkadiyt wrote:
| See also this discussion about the original source:
| https://news.ycombinator.com/item?id=36350693
___________________________________________________________________
(page generated 2023-06-17 23:01 UTC)