Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Linux Kernel Security is Lacking
Jason Miller, 2005-02-02

Recent events have shown that the way security in the Linux kernel is handled is broken, and it needs to be fixed right now.

Comments Mode:
Linux Kernel Security is Lacking 2005-02-02
Anonymous (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Anonymous (5 replies)
Linux Kernel Security is Lacking 2005-02-05
Anonymous
Linux Kernel Security is Lacking 2005-02-06
Anonymous
"The numbers" and (deliberate?) failure to undestand what linux is 2005-02-07
RedHat not Linux User. (1 replies)
Re: The "numbers" and (deliberate?) failure to undestand what linux is 2005-02-07
Jason V. Miller (Author) (1 replies)
Vendors and kernel security 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-03
Anonymous (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Jason V. Miller (Author)
Linux Kernel Security is Lacking 2005-02-03
Todd Knarr (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Jason V. Miller (Author) (1 replies)
Linux Kernel Security is Lacking 2005-02-05
Todd Knarr (1 replies)
Linux Kernel Security is Lacking 2005-02-09
Joe Borsits (1 replies)
Linux Kernel Security is Lacking 2005-02-09
Todd Knarr (1 replies)
Linux Kernel Security is Lacking 2005-02-10
Joe Borsits
Linux Kernel Security is Lacking 2005-02-03
Anonymous (1 replies)
Linux Kernel Security is Lacking 2005-02-04
Jason V. Miller (Author) (1 replies)
Linux Kernel Security is Lacking 2005-02-05
RVGeerligs
Really? 2005-02-03
Anonymous
I eagerly await... 2005-02-03
Anonymous (5 replies)
I eagerly await... 2005-02-03
Anonymous
I eagerly await... 2005-02-03
Anonymous (2 replies)
I eagerly await... 2005-02-04
Anonymous
I eagerly await... 2005-02-07
Anonymous
I eagerly await... 2005-02-04
Anonymous
I eagerly await... 2005-02-04
Anonymous (1 replies)
I eagerly await... 2005-02-09
Anonymous
Re: I eagerly await... 2005-02-04
Anonymous (1 replies)
Re: I eagerly await... 2005-02-04
Jason V. Miller
Computer Security is Oxymoron - FYI reading here: 2005-02-03
Anonymous (1 replies)
Computer Security is Oxymoron No Longer 2005-02-07
Kernel hacker
So, what now about kernel security? 2005-02-03
Anonymous (2 replies)
So, what now about kernel security? 2005-02-04
Jason V. Miller (Author) (2 replies)
Linux Kernel Security is Lacking 2005-02-04
TJ (1 replies)
flamer ! is not having an hidden mailing = we do'n't care about security 2005-02-04
Alban Browaeys (1 replies)
your point is based on one idea :
security = hidden mailing list

This has been discussed in the LKML quite extnsively. You can argue on that but only telling your point of view while removing even the lead upstream developper comments, you are only doing politics.

The point is that security related people used to dealing with big company refuse to send security patches on the open mailing list. The problem arised because a developper sent his patch to the personal email address of Linus Torvald. Then waited a few days and said the linux kernel developpers did not respond, they don't care about security issue.
Did he even ask where to sent his security patches on the main mailing list ? No he did it after publishing the vulnerability .

Most security problems are bugs in the design or implementations. They where managed as the other in the open mailing list.
The discussion changed to how can distribution security teams work more closely with upstream. This is the issue that is being discussed upon. Not "hey we should care about security lets set up a private mailing list" ...

Your arguments are good. If only you took the time to read the big thread about that , and arguments on what was there , not only on the first emotive email.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/296/30346#30346
Linux Kernel Security is Lacking 2005-02-04
Keshav Jha
Linux Kernel Security is Lacking 2005-02-05
Anonymous
OpenBSD slogan 2005-02-06
Anonymous
Linux Kernel Security is Lacking 2005-02-08
Anonymous (1 replies)
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Discussed on linux-kernel 2005-02-09
Anonymous
security@kernel.org 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Contact the module developer? 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-09
Anonymous
Linux Kernel Security is Lacking 2005-02-10
Khawar Nehal







 

Privacy Statement
Copyright 2009, SecurityFocus