Post B6KZH8lF7BSarD9oHo by wolf480pl@mstdn.io
 (DIR) More posts by wolf480pl@mstdn.io
 (DIR) Post #B6KWTuOtWC40Dm6JMm by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       Is it better ifa) some rando watches security fixes being committed to the Linux kernel's git repo, develops exploits within hours of seeing them, and publishes them for everyone to use, orb) only nation states do that, and they don't share these exploits with anyone?Like, for an average computer-using company, obviously (b) is better because nation states are unliekly to target them.But for the rest of us?
       
 (DIR) Post #B6KWxdZwcqysjkRexk by xerz@soc.masfloss.net
       0 likes, 0 repeats
       
       @wolf480pl basically war dynamicsalas
       
 (DIR) Post #B6KWxdkZzJUJGjQ9XU by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @xerz uh, pls elaborate
       
 (DIR) Post #B6KXYkMiM8c0V2x5Ie by sqrt2@chaos.social
       0 likes, 0 repeats
       
       @wolf480pl i think i preferc) some rando watches security fixes being committed to the kernel repo, develops exploits within hours of seeing them and posts them to linux-distros telling them to backport the fix until monday/tomorrow/whenever and push it through the pipelines because the poc goes live then
       
 (DIR) Post #B6KXduhLMnFfzh44si by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @sqrt2 that'd be nice
       
 (DIR) Post #B6KYz7zTF08hFsDtsu by sqrt2@chaos.social
       0 likes, 0 repeats
       
       @wolf480pl bonus: we might actually get a cve
       
 (DIR) Post #B6KZH8lF7BSarD9oHo by wolf480pl@mstdn.io
       0 likes, 0 repeats
       
       @sqrt2 Ever since Linux Kernel has become a CNA, it assigns CVEs to any bugfix that has the slightest chance of being a vuln anyway.Also, oftentimes (1 of the 2 cases I've seen) it's a vuln that was discovered by someone else, reported, is under embargo, has CVE assigned, and linux-distros is already aware of it.