[HN Gopher] Linux kernel security work
       ___________________________________________________________________
        
       Linux kernel security work
        
       Author : chmaynard
       Score  : 20 points
       Date   : 2026-01-02 21:31 UTC (1 hours ago)
        
 (HTM) web link (www.kroah.com)
 (TXT) w3m dump (www.kroah.com)
        
       | JCattheATM wrote:
       | Their view that security bugs are just normal bugs remains very
       | immature and damaging. It it somewhat mitigated by Linux having
       | so many eyes on it and so many developers, but a lot of problems
       | in the past could have bee avoided if they adopted the stance the
       | rest of the industry recognizes as correct.
        
         | tptacek wrote:
         | From their perspective, on their project, with the constraints
         | they operate under, bugs are just bugs. You're free to
         | operationalize some other taxonomy of bugs in your
         | organization; I certainly wouldn't run with "bugs are just
         | bugs" in mine (security bugs are distinctive in that they're
         | paired implicitly with adversaries).
         | 
         | To complicate matters further, it's not as if you could rely on
         | any more "sophisticated" taxonomy from the Linux kernel team,
         | because they're not the originators of most Linux kernel
         | security findings, and not all the actual originators are
         | benevolent.
        
           | rwmj wrote:
           | For sure, but you don't need to file CVEs for every regular
           | bug.
        
         | beanjuiceII wrote:
         | did you read it? because that's not their view at all
        
       ___________________________________________________________________
       (page generated 2026-01-02 23:00 UTC)