|
|
Log in / Subscribe / Register

A turning point for CVE numbers

A turning point for CVE numbers

Posted Feb 15, 2024 17:00 UTC (Thu) by wtarreau (subscriber, #51152)
In reply to: A turning point for CVE numbers by bluca
Parent article: A turning point for CVE numbers

> companies will just stop using Linux in their products

Maybe actually that would be the best way to get rid of the tiny portion of perpetual complainers who don't want to miss any single security notification but are upset when the most likely ones are going to be reported because there are too many. Or their level of expectations just means that they want for free something that costs a lot of man power and that from the beginning they should have gone with paid distros whose job is to invest more time in that triage.


to post comments

A turning point for CVE numbers

Posted Feb 15, 2024 18:55 UTC (Thu) by farnz (subscriber, #17727) [Link] (5 responses)

Or their level of expectations just means that they want for free something that costs a lot of man power

This underlies a lot of people's complaints about open source projects; you get something for free that's anything from 10% to 95% of what you need, and then complain that the remaining parts are expensive to do. They don't account for the savings when compared to licensing a commercial product in that; they just want the open source product to be a free drop-in replacement for the thing they'd otherwise be paying for, and they don't want to spend on it because then it's not "free", and the accounting gets hard.

A turning point for CVE numbers

Posted Feb 16, 2024 0:25 UTC (Fri) by bluca (subscriber, #118303) [Link] (4 responses)

Nah, this is the opposite: if the plan is to spend resources to flood the system with bogus CVEs, then just don't. Much better to not do anything at all, and leave security triaging to somebody else.

A turning point for CVE numbers

Posted Feb 16, 2024 10:12 UTC (Fri) by farnz (subscriber, #17727) [Link] (3 responses)

That ship sailed a long time ago; the system is currently being flooded with bogus CVEs by "security" people looking to pad their CVs with a large number of discovered CVEs. At least this way round, the kernel controls the flood, instead of being flooded by other people's demands.

A turning point for CVE numbers

Posted Feb 16, 2024 11:06 UTC (Fri) by bluca (subscriber, #118303) [Link] (2 responses)

That's the narrative the kernel developers are pushing - it's complete nonsense of course. Yes there is some abuse, like with any other public input system, but it's nowhere near "flooding" levels. As anybody managing any distro can attest, the noise ratio is very low.

A turning point for CVE numbers

Posted Feb 16, 2024 12:00 UTC (Fri) by pizza (subscriber, #46) [Link] (1 responses)

> That's the narrative the kernel developers are pushing - it's complete nonsense of course.

Look, you may have expertise in some areas (eg knowledge of how EU regs work etc) but that does not automatically make you the domain expert in other areas.

Especially when you're digging in on a position directly contrary to the literal "this is why we're doing this" words coming out of the actual domain experts' mouths.

A turning point for CVE numbers

Posted Feb 16, 2024 12:17 UTC (Fri) by bluca (subscriber, #118303) [Link]

I am part of a team that manages an internal distribution that, among other things, deals with CVEs weekly. Is that enough "street creds" to call bullshit?

Look, every single Linux distribution has systems and teams to deal with CVEs and security updates. Of course there is abuse, of course there are bogus ones being raised. It is not 80%, it is not the majority, it is not flooding. Could things be improved? Sure. Flooding the system with a bogus CVE for every commit is not the way to do that, quite the opposite.

A turning point for CVE numbers

Posted Feb 16, 2024 7:54 UTC (Fri) by jikos (subscriber, #43140) [Link]

> ... they should have gone with paid distros whose job is to invest more time in that triage.

The problem is, that with this new system, paid distros are going to suffer a big time (with no benefit to anybody at all).

We'll have to put a lot of productive and creative (upstream) work on hold in order to have enough resources to sort out the unnecessary havoc that LTS team is apparently going to create by DoSing the world with a truckload of irrelevant CVEs.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds