LWN.net Logo

Handling kernel security problems

Handling kernel security problems

Posted Jul 16, 2008 21:35 UTC (Wed) by flewellyn (subscriber, #5047)
Parent article: Handling kernel security problems

It is worth noting that those distributors have not been doing a whole lot of complaining about how security fixes are handled now. Instead, the complaining has come, primarily, from the maintainers of the out-of-tree grsecurity project which, from a suitably cynical point of view, could be seen to benefit from raising the profile of Linux kernel security problems.

Given the actions of those people when they posted here, I don't think that viewpoint requires any great degree of cynicism. It seems quite accurate.


(Log in to post comments)

Handling kernel security problems

Posted Jul 16, 2008 22:38 UTC (Wed) by spender (guest, #23067) [Link]

The PaX team certainly benefits the most from it -- given that they don't get paid a cent for
any of the work they do.  So in what way do they benefit again?  Name recognition?  Shucks,
that doesn't pan out either.  Sorry but this is nothing but a way to avoid what's really the
problem here by trying to discredit the messenger (who btw has been doing this for free for 8
years now and is to thank for all the actually useful security improvements you're using right
now that have been copied from it by everyone else).

-Brad

Handling kernel security problems

Posted Jul 17, 2008 11:17 UTC (Thu) by clugstj (subscriber, #4020) [Link]

Obviously the benefit isn't money - everyone knows that.  I don't see why fame (name
recognition) can't be the reason.

Yours is a straw man argument.

Handling kernel security problems

Posted Jul 17, 2008 20:50 UTC (Thu) by lysse (subscriber, #3190) [Link]

For some reason I'm reminded of this quote from "A Man for All Seasons":

MORE: (interested) Buy a man with suffering?

RICH: Impose suffering, and offer him... escape.

MORE: Oh. For a moment I thought you were being profound.

Human motivations can be complex and strange little beasts...

Handling kernel security problems

Posted Jul 16, 2008 22:54 UTC (Wed) by spender (guest, #23067) [Link]

And if you want to be "suitably cynical" I suppose the reason why the distributors haven't
been doing a whole lot of complaining about how security fixes are handled is because not
having as many disclosed security vulnerabilities in the Linux kernel makes it look like less
of a mess.

Even Linus says himself that "they mostly do a crap job at it, only focusing on a small
percentage (the ones that were considered to be "big issues")"

-Brad

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds