Remote
0
Followers
0
Following
23
Posts
Joined December 21, 2017
Posts
Replying to
@nicolasvivant@colter.social
@nicolasvivant@colter.social En l’occurrence il me semble que c’est deux choses différentes (et malheureusement pas incompatibles). Sur DirtyFrags il y a eu une tentative de divulgation responsable au moins.
Aussi, la coordination avec le noyau Linux est complexe (cf. les posts récents de Greg KH). Il y a tellement d’utilisateurs que ça devient compliqué de savoir avec qui faire de la coordination (les distributions commerciales, les distributions bénévoles, les CSP, les gouvernements…)
Open post
Replying to
@ccll@mamot.fr
@ccll@mamot.fr @ThierryJoffredo@mamot.fr oui gratouiller un peu l’intérieur de la prise avec un cure dent ou un trombone. Il y a souvent de la poussière et des fibres qui se logent dedans, c’est potentiellement lié ?
1
0
0
0
Open post
Replying to
@Di4na@hachyderm.io
@Di4na@hachyderm.io @gregkh@social.kernel.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @Viss@mastodon.social unfortunately I think there a lot of people (IT services) having been burned more badly by updating than not updating. I still think people should do it (especially because mass vulnerability exploitation seems to usually happen for stuff fixes months ago) but still just blaming them for not doing doesn’t work. Not sure it’s really the Linux kernel the concern here though.
0
1
0
0
Open post
Replying to
@Di4na@hachyderm.io
@Di4na@hachyderm.io @gregkh@social.kernel.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @Viss@mastodon.social that’s call risk management and it’s not necessarily a bad thing. And people have been (and still are) burned by updates. I don’t think it’s a good reason to never update but I can’t blame people for being cautious, especially since I’m not in their shoes and don’t know all their concerns
0
1
0
0
Open post
Replying to
@gregkh@social.kernel.org
@gregkh@social.kernel.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @Viss@mastodon.social End users in IT systems either large or small corps, administrations etc. don’t just get their kernel from kernel.org and rebuild them. They use kernel binaries, usually from a distribution or maybe rebuilt from by their IT.
Most the various containers runtime similarly run on distro kernels.
Not sure the ratio of running kernels coming straight from kernel.org but I’d guess small
1
0
0
0
Open post
Replying to
@joshbressers@infosec.exchange
@joshbressers@infosec.exchange @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social aren’t the "users" missing from the equation? In the end we do it for them and we need them to fix their systems, and we need it to be easy for them to fix their systems.
Also there are a lot of open source companies, whether software developers, support providers, integrators, administrators, or a combination.
Also governments which are users, regulators, contributors…
Economics are hard indeed
1
2
0
0
Open post
Replying to
@adulau@infosec.exchange
@adulau@infosec.exchange well they’re bots, they just enumerate *everything* :/
1
0
0
0
Open post
Replying to
@Aissen@social.treehouse.systems
@Aissen@social.treehouse.systems The process is already pretty scripted but there's still some manual things to do (whether in the kernel packaging or in the DSA processing).
On Apr 30th v6.12.85 was tagged at 1116Z and the DSA was sent at 2005Z. I'm unsure we can do much faster.
note: I didn't do anything this time, it's mainly the work of Salvatore Bonaccorso (as a volunteer): https://salsa.debian.org/kernel-team/linux/-/merge_requests/1895
1
0
0
0
Open post
Replying to
@corsac@mastodon.social
@gregkh@social.kernel.org @deftpunk@fosstodon.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @Viss@mastodon.social
Still, it leaves a bit of a bitter taste. Not sure how we can do better though.
1
1
0
0
Open post
Replying to
@corsac@mastodon.social
@gregkh @deftpunk @joshbressers @wdormann @Viss
As Greg mentioned, vulnerability coordination is difficult, and it's hard to draw a line about who to include and who not to.
Maybe the researchers thought they did the right thing by notifying the kernel security team (and they did), and they thought it was enough. But I don't think it's written anywhere that the kernel security team will coordinate with downstream (or anyone else), and again I'm not sure it's really possible.
2
1
0
0
Open post
Replying to
@gregkh@social.kernel.org
@gregkh @deftpunk @joshbressers @wdormann @Viss I think we (the distro security teams, speaking as a member of the Debian one) would have liked a heads up, including maybe to help backporting to the stable kernel we run. We didn't have that heads up, we discovered the thing like everyone else.
3
1
0
0
Open post
Replying to
@EUCommission@ec.social-network.europa.eu
@EUCommission Similar thing with iOS and the cloud APIs. What about using Photos with a Nextcloud instance?
6
0
0
0
Open post
Replying to
@magcbertrand@social.sciences.re
@magcbertrand On avait déjà l'UBO et l'UBS, maintenant l'Université de Bretagne Extrème-Orientale ?
0
0
0
0
Open post
Replying to
@cazencott@lipn.info
@cazencott@lipn.info yeah I’m kind of in the same situation :/ thanks though!
1
0
0
0
Open post
Replying to
@cazencott@lipn.info
@cazencott@lipn.info still having trouble reconciling this with that: https://blog.mozilla.org/en/privacy-security/ai-security-zero-day-vulnerabilities/
My timeline seems to be half and half about that…
1
2
0
0
Open post
Open post
Open post
Replying to
@GrapheneOS@grapheneos.social
@GrapheneOS @watchfulcitizen Thanks for the link. I don't really see the threats there or mentions of backdoors to be included by the project. And Johanna Brousse seemed to be pretty reasonable when she closed the SSTIC conference last year (https://www.sstic.org/2025/presentation/cloture_2025/)
0
1
0
0
Open post
Replying to
@watchfulcitizen@goingdark.social
@watchfulcitizen @GrapheneOS Can you share the source for the alleged threats and the refusal to add backdoors?
2
1
0
0
Open post
Replying to
@bagder@mastodon.social
@bagder@mastodon.social I wonder if @sovtechfund@mastodon.social could step-in
10
0
1
0
Open post
Replying to
@sbi@toot.berlin
@sbi except it’s not an either: nuclear power and batteries don't really play the same role in the grid, are they? Anyway I wasn’t trying to convince you, and if we’re on the "what I prefer" trend we’re out of the engineering thread and I don’t think arguing there makes much sense.
0
1
0
0
Open post
Replying to
@CatherineFlick@mastodon.me.uk
@CatherineFlick@mastodon.me.uk Children still do « Tchou tchou » when imitating trains so I'm not so sure about that.
0
0
0
0
Remote instance
mastodon.social
Open on original server