(no title)
parmezan | 4 years ago
I get responsible disclosure is important, but should we not give people some more opportunity to patch, which will always take some time?
Just curious.
Also, nice work and interesting find!
parmezan | 4 years ago
I get responsible disclosure is important, but should we not give people some more opportunity to patch, which will always take some time?
Just curious.
Also, nice work and interesting find!
staticassertion|4 years ago
It puts me, as a defender, at an insane disadvantage. Attackers have the time, incentives, and skills to look at commits for vulns. I don't. I don't get paid for every commit I look at, I don't get value out of it.
This backwards process pushed by Greg KH and others upstream needs to die ASAP.
weberer|4 years ago
nickelpro|4 years ago
The announcement only serves to let the rest of the public know about this and incentivize them to upgrade.
amluto|4 years ago
(Thanks Max for handling this well and politely and for putting up with everyone’s conflicting opinions.)
staticassertion|4 years ago
ilnaszeycure|4 years ago
I can't help but physically shake my head as I write this. I can't imagine actually asking people to try to play pretend security through obscurity because folks still can be arsed to implement some sort of reasonable update strategy. I have enough experience in tiny and huge shops to say that it's a matter of prioritization and it's just a blatant form of technical debt and poor foresight.
wtarreau|4 years ago