Some awesome compiler, linkers and toolchain hackers I know are unemployed at the moment due to the Oracle layoff. I'm unable to absorb any in my team unfortunately, but if you have openings in your company, please let me know and I'll try to patch y'all up with some awesome toolchain hackers.
Remote
Siddhesh Poyarekar
@siddhesh_p@mastodon.social
Ice cream sandwich connoisseur | compiler cat whisperer | cursed projects specialist
0 Followers
0 Following
7 Posts
Joined November 08, 2019
Website:
Brainless C Monkey:
brainlesscmonkey.club
Open post
Replying to @joshbressers@infosec.exchange
@joshbressers@infosec.exchange @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social this may be true for the Linux kernel, especially with the resignation that the Linux CNA will assign a CVE for most reports, but it doesn't align with my anecdotal experience as glibc CNA. It's likely because we have significantly less volume (12 so far this year, with roughly twice as many reports) and we tend to be picky about what we assign to a CVE id to.
I'd argue that the kernel is special here and doesn't represent the ecosystem.
2
4
0
0
Open post
Replying to @siddhesh_p@mastodon.social
@joshbressers@infosec.exchange @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social and $0.02, security policies are pretty much our first line of defence for security issues for the GNU toolchain, where we try to identify clearly what constitutes a security issues. It also makes it clear to users how to use the tools and API securely. I don't think there's a reasonable equivalent for that for the kernel. One could try, but given that it's a privileged program that's involved in everything, it would be a largely pointless effort.
1
2
0
0
Open post
Replying to @siddhesh_p@mastodon.social
@joshbressers@infosec.exchange @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social but I'd love to see someone trying, it would be an interesting grad research project I think.
1
0
0
0
Open post
Replying to @joshbressers@infosec.exchange
@joshbressers@infosec.exchange @gregkh@social.kernel.org @wdormann@infosec.exchange @Viss@mastodon.social I'm not so sure, I just think there's a vast enough distance between the Linux kernel experience and pretty much any other project when it comes to security handling: volume, nature of reports, density of known exploitable issues. etc. that there aren't really any reasonable parallels to be drawn. I wouldn't think of throwing security policies, CVE evaluation or coordinated disclosure out because the kernel can't find a way to do it in a way that they like.
1
2
0
0
Open post
I was today years old when I discovered Eggstatic, entirely by accident. Apparently they opened their Waterloo location only last year in November but I've dismissed the ones in GTA all these years as a standard north american breakfast place.
It's a Palestinian owned breakfast restaurant chain in Canada (primarily Ontario although it looks like they're expanding fast) that serves middle eastern fare. If you find one within reach, you'd be doing yourself a disservice by not going.
1
0
1
0
Open post
Replying to @nixCraft@mastodon.social
@nixCraft@mastodon.social @vitaut@mastodon.social look, bash.
0
0
0
0