|
|
Log in / Subscribe / Register

A fuzzy issue of responsible disclosure

A fuzzy issue of responsible disclosure

Posted Aug 16, 2022 20:48 UTC (Tue) by mcatanzaro (subscriber, #93033)
In reply to: A fuzzy issue of responsible disclosure by Wol
Parent article: A fuzzy issue of responsible disclosure

The comments on this story might themselves be worthy of an LWN story. Claiming that reporting *legitimate* security bugs is akin to harassment is pretty wild. I don't think anybody expects you to fix all those bugs, but the public deserves to know about them, and it's hard to think of a better place than the upstream bug tracker. I suppose there are plenty of other ways researchers can report vulnerabilities if you don't want your bug tracker used that purpose, though.

Ideally, they would receive CVEs so they can be tracked, but we all know only a tiny minority of security vulnerabilities actually receive CVEs.

It's unusual to receive the quantity of fuzzer reports that you are receiving. It indicates a very serious safety problem. Even web engines, which are full of vulnerabilities and fuzzed regularly by security researchers, do not deal with anywhere near that many fuzzer reports.


to post comments

A fuzzy issue of responsible disclosure

Posted Aug 16, 2022 22:41 UTC (Tue) by Wol (subscriber, #4433) [Link] (1 responses)

I'm talking hypothetically. But running a fuzzer on a code base that hasn't been fuzzed before could probably generate a stream like that without any problem at all.

I once took over a program. I think it took me six months to clean up all the problems revealed just by upping the compiler warning level. And the comments earlier in the article imply that people are being hit by exactly this - projects being flooded with fuzzer reports.

> Claiming that reporting *legitimate* security bugs is akin to harassment is pretty wild.

Not when it's done with no regard whatsoever for the *people* running that project. If you're talking about faceless corporations then of course it APPEARS to be impersonal. But that only makes it worse for the real individuals on the receiving end.

What's that definition of hell? Responsibility without authority? If you are being held accountable for something you have no control over, then that's hell. That's harassment. And legitimate or not, flooding A PERSON with bug reports - serious or not - beyond their ability to cope is not acceptable.

I was fine - that 6-month cleanup was something I opted in to - I felt the company's development practices were extremely lackadaisical and it was my choice to fix it, but if I'd had it dumped on me and been pressured to get it fixed yesterday, then ...

Cheers,
Wol

A fuzzy issue of responsible disclosure

Posted Aug 16, 2022 23:34 UTC (Tue) by rahulsundaram (subscriber, #21946) [Link]

> Not when it's done with no regard whatsoever for the *people* running that project

It may be slightly problematic behavior but certainly not something you can call harassment. That's reaching way too far.

A fuzzy issue of responsible disclosure

Posted Aug 25, 2022 2:10 UTC (Thu) by milesrout (guest, #126894) [Link] (1 responses)

If Wol making awful uninformed comments was worthy of an LWN story, then LWN would not have time to write about anything else.

A fuzzy issue of responsible disclosure

Posted Aug 25, 2022 4:19 UTC (Thu) by Wol (subscriber, #4433) [Link]

:-)

Cheers,
Wol


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds