Post B6Ahuuwuk551emUm5w by rene_mobile@infosec.exchange
 (DIR) More posts by rene_mobile@infosec.exchange
 (DIR) Post #B6Ahuuwuk551emUm5w by rene_mobile@infosec.exchange
       1 likes, 0 repeats
       
       Releasing a universal #Linux #kernel #exploit with very little or even no previous time to distribute a patch through distributions is not cool. Doing it on the day before a weekend - on two weekends in a row - is just being an asshole. Looking at you, #CopyFail and #DirtyFrag. You may think it helps your PR, that people will queue to use your cool new AI/agentic/whatever tool because you found the bug. You may think that releasing the full exploit because somebody else was even quicker with "leaking" your cool find makes it right. You're wrong. This is neither responsible nor coordinated disclosure. In security, we've tried to learn the hard lessons on keeping in-production, live systems on a global scale safer. Yes, those bugs have existed for a long time in the kernel source. Yes, other bad actors may already have found them. But you're shining a light on it *and* giving every script kiddie in the world a working exploit to point their mass scans at. That's dangerous. There's a reason why the normal process is to reach out at least to the most widely installed distributions before releasing the bug details publicly. There's a reason why 90 days is a good default - it allows downstream percolation of patches. You can still get the credit. This way, you only create stress for admins.[For a little relief, refer to https://www.tomshardware.com/tech-industry/cyber-security/dirty-frag-exploit-gets-root-on-most-linux-machines-since-2017-no-patches-available-no-warning-given-copy-fail-like-vulnerability-had-its-embargo-broken for a quick mitigation, because updating kernels and rebooting a fleet of hosts just takes time, weekend or not. #HugOps]
       
 (DIR) Post #B6P9Zg9M5X7gbcPlHk by rayk@techhub.social
       0 likes, 0 repeats
       
       @rene_mobile I thought I read that dirtyfrag was originally disclosed responsibly, with a delay before publication, but someone else leaked it, so the discoverer had to publish so that people would know. What I read said that was pretty much standard procedure. Is there some article that’s saying this wasn’t the case?
       
 (DIR) Post #B6P9ZgRR0JaJVgsCSu by rene_mobile@infosec.exchange
       0 likes, 1 repeats
       
       @rayk Leaking the bug (potentially to some limited list) is still not the same as leaking the full exploit and making a lot of noise about it. Even it the exploit can be recreated, why make it so easy for everybody to exploit it immediately? Sure, there's always lots of gray in the spectrum of coordinated disclosure. But from what I can see, they didn't seem to try very hard to help people get their systems into a safer state. The bug release page first and foremost points out how easy the exploit it and on how many distributions it works. This is showing off, and not making systems more secure.Yeah, I am not amused.