linux-kernel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Linus Torvalds <torvalds@osdl.org>
To: Dave Jones <davej@redhat.com>
Cc: Marcelo Tosatti <marcelo.tosatti@cyclades.com>,
	Greg KH <greg@kroah.com>, Chris Wright <chrisw@osdl.org>,
	akpm@osdl.org, alan@lxorguk.ukuu.org.uk,
	linux-kernel@vger.kernel.org
Subject: Re: thoughts on kernel security issues
Date: Wed, 12 Jan 2005 18:09:31 -0800 (PST)	[thread overview]
Message-ID: <Pine.LNX.4.58.0501121750470.2310@ppc970.osdl.org> (raw)
In-Reply-To: <20050112205350.GM24518@redhat.com>



On Wed, 12 Jan 2005, Dave Jones wrote:
> 
> Who would be on the kernel security list if it's to be invite only ?
> Is this just going to be a handful of folks, or do you foresee it
> being the same kernel folks that are currently on vendor-sec ?

I'd assume that it's as many as possible. The current vendor-sec kernel
people _plus_ anybody else who wants to.

> My first thought was 'Chris will forward the output of security@kernel.org
> to vendor-sec, and we'll get a chance to get updates built'. But you
> seem dead-set against any form of delayed disclosure, which has the
> effect of catching us all with our pants down when you push out
> a new kernel fixing a hole and we don't have updates ready.

Yes, I think delayed disclosure is broken. I think the whole notion of 
"vendor update available when disclosure happens" is nothing but vendor 
politics, and doesn't help _users_ one whit.  The only thing it does is 
allow the vendor to point fingers and say "hey, we have an update, now 
it's your problem".

In reality, the user usually needs to have the update available _before_
the disclosure anyway. Preferably by _months_, not minutes.

So I think the whole vendor-sec thing is not helping users at all, it's 
purely a "vendor embarassment" thing. 

> If you turned the current model upsidedown and vendor-sec learned
> about issues from security@kernel.org a few days before it'd at
> least give us *some* time, as opposed to just springing stuff
> on us without warning.

I think kernel bugs should be fixed as soon as humanly possible, and _any_
delay is basically just about making excuses. And that means that as many
people as possible should know about the problem as early as possible,
because any closed list (or even just anybody sending a message to me
personally) just increases the risk of the thing getting lost and delayed
for the wrong reasons.

So I'd not personally mind some _totally_ open list. No embargo at all, no 
limits on who reads it. The more, the merrier. However, I think my 
personal preference is pretty extreme in one end, and I also think that 
vendor-sec is extreme in the other. So there is probably some middle 
ground.

Will it make everybody happy? Hell no. Nothing like that exists. Which is 
why I'm willing to live with an embargo as long as I don't feel like I'm 
being toyed with.

And hey, vendor-sec works. I feel like vendor-sec just toys with me, which
is why I refuse to have anything to do with it, but it's entirely possible
that the best solution is to just ignore my wishes. That's OK. I'm ok with
it, vendor-sec is ok with it, nobody is _happy_ with it, but it's another
compromise. Agreeing to disagree is fine too, after all.

So it's embarrassing to everybody if the kernel.org kernel has a security
hole for longer than vendor kernels, but at the same time, most _users_
run vendor kernels anyway, so maybe the current setup is the proper one,
and the kernel.org kernel _should_ be the last one to get the fix.  
Whatever. I happen to believe in openness, and vendor-sec does not. It's
that simple.

But if we're seriously looking for a middle ground between my "it should 
be open" and vendor-sec "it should be totally closed", that's where my 
suggestions come in. Whether people _want_ to look for a middle ground is 
the thing to ask first..

For example, having an arbitrarily long embargo on actual known exploit
code is fine with me. I don't care. If I have to promise to never ever
disclose an exploit code in order to see it, I'm fine with that - but I
refuse to delay the _fix_ by more than a few days, and even that "few
days" goes out the window if somebody else has knowingly delayed giving
the fix or problem to me in the first place.

This is not just about sw security, btw. I refuse to sign NDA's on hw 
errata too. Same deal - it may mean that I get to know about the problem 
later, but it also means that I don't have to feel guilty about knowing of 
a problem and being unable to fix it. And it means that people can trust 
_me_ personally.

		Linus

  parent reply	other threads:[~2005-01-13  2:09 UTC|newest]

Thread overview: 212+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-01-12 17:48 thoughts on kernel security issues Chris Wright
2005-01-12 15:06 ` Marcelo Tosatti
2005-01-12 18:49   ` Chris Wright
2005-01-12 18:05 ` Linus Torvalds
2005-01-12 18:44   ` Chris Wright
2005-01-12 18:57     ` Linus Torvalds
2005-01-12 19:21       ` Chris Wright
2005-01-12 20:59       ` Jesper Juhl
2005-01-12 21:27       ` Greg KH
2005-01-12 18:51   ` Greg KH
2005-01-12 19:01     ` Linus Torvalds
2005-01-12 16:12       ` Marcelo Tosatti
2005-01-12 20:00         ` Linus Torvalds
2005-01-12 17:42           ` Marcelo Tosatti
2005-01-13 15:36             ` Alan Cox
2005-01-13 17:22               ` Marcelo Tosatti
2005-01-13 21:20                 ` Alan Cox
2005-01-13 17:52               ` Florian Weimer
2005-01-13 19:42               ` Marek Habersack
2005-01-13 19:19                 ` Alan Cox
2005-01-13 20:44                   ` Marek Habersack
2005-01-14 10:22                     ` Wichert Akkerman
2005-01-14 12:10                       ` Julian T. J. Midgley
2005-01-14 14:52                         ` Florian Weimer
2005-01-14 15:12                           ` Julian T. J. Midgley
2005-01-15  0:33                             ` Alan Cox
2005-01-14 13:55                       ` Marek Habersack
2005-01-13 19:50                 ` Chris Wright
2005-01-13 20:29                   ` Marek Habersack
2005-01-13 19:41                     ` Alan Cox
2005-01-13 20:57                       ` Arjan van de Ven
2005-01-13 21:22                         ` Linus Torvalds
2005-01-13 21:15                           ` Alan Cox
2005-01-13 22:41                             ` Linus Torvalds
2005-01-13 21:41                           ` Arjan van de Ven
2005-01-13 21:02                       ` Marek Habersack
2005-01-13 21:30                         ` Dave Jones
2005-01-13 21:48                           ` Marek Habersack
2005-01-13 22:06                             ` Dave Jones
2005-01-13 22:21                               ` Marek Habersack
2005-01-13 23:30                               ` Jesper Juhl
2005-01-15  0:34                                 ` Alan Cox
2005-01-15  2:56                                   ` Marcin Dalecki
2005-01-13 20:03                 ` Dave Jones
2005-01-13 20:10                   ` Linus Torvalds
2005-01-13 19:27                     ` Alan Cox
2005-01-13 21:03                       ` Linus Torvalds
2005-01-13 21:25                         ` Alan Cox
2005-01-13 22:47                           ` Linus Torvalds
2005-01-13 23:15                           ` Chris Wright
2005-01-14 18:34                         ` Theodore Ts'o
2005-01-14 19:15                           ` Linus Torvalds
2005-01-14 22:13                             ` Theodore Ts'o
2005-01-14 22:51                               ` Linus Torvalds
2005-01-15  0:34                                 ` Alan Cox
2005-01-15  4:19                                   ` Linus Torvalds
2005-01-15  5:36                                 ` Rik van Riel
2005-01-18 22:27                             ` Bill Davidsen
2005-01-19  2:34                               ` Alban Browaeys
2005-01-19 19:13                                 ` Bill Davidsen
2005-01-13 20:32                   ` Marek Habersack
2005-01-12 20:27           ` Chris Wright
2005-01-12 20:57             ` Greg KH
2005-01-13 15:36               ` Alan Cox
2005-01-12 21:20             ` Andrea Arcangeli
2005-01-12 20:28           ` Linus Torvalds
2005-01-12 18:03             ` Marcelo Tosatti
2005-01-13  3:18             ` Christian
2005-01-12 20:53           ` Dave Jones
2005-01-12 20:59             ` Greg KH
2005-01-13  2:09             ` Linus Torvalds [this message]
2005-01-13  2:28               ` Andrew Morton
2005-01-13  2:51                 ` Linus Torvalds
2005-01-13  3:05                   ` David Blomberg
2005-01-13  2:56                 ` Greg KH
2005-01-13  3:01                 ` Chris Wright
2005-01-13  3:35                 ` Dave Jones
2005-01-13  3:42                   ` Andrew Morton
2005-01-13  3:54                     ` Chris Wright
2005-01-13  4:49                     ` William Lee Irwin III
2005-01-13  6:54                       ` Andrew Morton
2005-01-13  7:19                         ` William Lee Irwin III
2005-01-13  7:25                         ` Matt Mackall
2005-01-13  4:48                   ` Linus Torvalds
2005-01-13  5:51                     ` Barry K. Nathan
2005-01-13  7:28                     ` Matt Mackall
2005-01-13  7:42                       ` Willy Tarreau
2005-01-13  8:02                         ` David Lang
2005-01-13 10:05                           ` Willy Tarreau
2005-01-13  8:23                     ` Christoph Hellwig
2005-01-13 16:38                       ` Linus Torvalds
2005-01-13 16:12                         ` Alan Cox
2005-01-13 17:33                           ` Linus Torvalds
2005-01-13 17:49                             ` Chris Wright
2005-01-13 18:53                             ` Alan Cox
2005-01-13 18:59                             ` John Richard Moser
2005-01-13 19:22                               ` Norbert van Nobelen
2005-01-13 19:35                                 ` John Richard Moser
2005-01-13 19:46                               ` Linus Torvalds
2005-01-13 19:57                                 ` John Richard Moser
2005-01-14 12:39                             ` Horst von Brand
2005-01-14 15:45                               ` Linus Torvalds
2005-01-14 15:52                                 ` Arjan van de Ven
2005-01-14 15:57                                 ` Stephen Smalley
2005-01-14 16:17                                   ` Stephen Smalley
2005-01-15  0:33                                 ` Alan Cox
2005-01-13 17:01                         ` Arjan van de Ven
2005-01-13 17:19                           ` Linus Torvalds
2005-01-13 17:45                             ` Arjan van de Ven
2005-01-13 18:31                             ` John Richard Moser
2005-01-19 10:30                               ` Ingo Molnar
2005-01-19 17:20                                 ` John Richard Moser
2005-01-19 17:47                                   ` Ingo Molnar
2005-01-19 18:35                                     ` John Richard Moser
2005-01-19 18:55                                       ` Arjan van de Ven
2005-01-19 19:46                                         ` John Richard Moser
2005-01-19 19:53                                           ` Arjan van de Ven
2005-01-20  8:46                                           ` [Lists-linux-kernel-news] " Ingo Molnar
2005-01-20  8:35                                       ` Ingo Molnar
2005-01-20 10:44                                       ` Ingo Molnar
2005-01-20 18:16                                         ` John Richard Moser
2005-01-20 18:53                                           ` Valdis.Kletnieks
2005-01-20 18:55                                           ` Arjan van de Ven
2005-01-20 19:17                                             ` John Richard Moser
2005-01-20 19:22                                           ` Christoph Hellwig
2005-01-20 21:24                                             ` John Richard Moser
2005-01-19 17:52                                   ` Arjan van de Ven
2005-01-19 18:50                                     ` John Richard Moser
2005-01-19 19:47                                       ` Valdis.Kletnieks
2005-01-19 19:53                                         ` Arjan van de Ven
2005-01-19 20:44                                           ` Valdis.Kletnieks
2005-01-19 20:12                                         ` John Richard Moser
2005-01-19 20:42                                           ` Valdis.Kletnieks
2005-01-19 21:03                                             ` John Richard Moser
2005-01-19 22:02                                               ` Splitting up grsecurity and PAX (was " Valdis.Kletnieks
2005-01-19 20:47                                           ` Diego Calleja
2005-01-25 15:05                                         ` Bill Davidsen
2005-01-25 15:52                                           ` Linus Torvalds
2005-01-25 17:27                                             ` Bill Davidsen
2005-01-25 18:01                                               ` John Richard Moser
2005-01-25 18:30                                                 ` Linus Torvalds
2005-01-25 18:37                                                   ` John Richard Moser
2005-01-25 18:57                                                     ` Dmitry Torokhov
2005-01-25 19:56                                                       ` John Richard Moser
2005-01-25 20:25                                                         ` J. Bruce Fields
2005-01-25 20:29                                                           ` John Richard Moser
2005-01-25 20:46                                                             ` J. Bruce Fields
2005-01-25 20:53                                                         ` Valdis.Kletnieks
2005-01-25 20:59                                                           ` John Richard Moser
2005-01-25 21:05                                                         ` linux-os
2005-01-25 21:20                                                           ` John Richard Moser
2005-01-26 15:15                                                           ` Jesse Pollard
2005-01-26 16:09                                                             ` Linus Torvalds
2005-01-26 19:15                                                               ` Olaf Hering
2005-01-26 19:28                                                                 ` Linus Torvalds
2005-01-26 19:38                                                                   ` Olaf Hering
2005-01-26 19:53                                                                     ` Linus Torvalds
2005-01-30 15:39                                                                 ` Alan Cox
2005-01-26 19:24                                                               ` John Richard Moser
2005-01-26 19:56                                                             ` Bill Davidsen
2005-01-27 16:37                                                               ` Jesse Pollard
2005-01-27 17:18                                                                 ` Zan Lynx
2005-01-27 22:18                                                                   ` Jesse Pollard
2005-01-27 23:20                                                                   ` Bill Davidsen
2005-01-27 23:36                                                                     ` John Richard Moser
2005-01-28  0:23                                                                       ` linux-os
2005-01-28  0:15                                                                   ` Krzysztof Halasa
2005-01-26  0:01                                                         ` Bill Davidsen
2005-01-26  0:40                                                           ` John Richard Moser
2005-01-25 19:05                                                     ` Linus Torvalds
2005-01-25 20:03                                                       ` John Richard Moser
2005-01-25 21:17                                                         ` Al Viro
2005-01-26 16:06                                                         ` Sytse Wielinga
2005-01-26 19:31                                                           ` John Richard Moser
2005-01-26 19:50                                                             ` Valdis.Kletnieks
2005-01-26 20:02                                                               ` John Richard Moser
2005-01-26 20:26                                                             ` Sytse Wielinga
2005-01-26 20:39                                                               ` John Richard Moser
2005-01-26 20:49                                                                 ` Sytse Wielinga
2005-01-25 18:08                                               ` Linus Torvalds
2005-01-14 21:57                             ` Russell King
2005-01-19 12:56                     ` Pavel Machek
2005-01-19 20:02                     ` Bill Davidsen
2005-01-13  4:49                   ` William Lee Irwin III
2005-01-13  5:19                     ` Dave Jones
2005-01-13 15:36                 ` Alan Cox
2005-01-13  3:25               ` Dave Jones
2005-01-13  3:53                 ` Marek Habersack
2005-01-13  5:38                   ` Barry K. Nathan
2005-01-13  8:59                     ` Florian Weimer
2005-01-13 15:31                       ` Barry K. Nathan
2005-01-13 15:36                       ` Alan Cox
2005-01-13 19:25                     ` thoughts on kernel security issuesiig Marek Habersack
2005-01-13 15:36                   ` thoughts on kernel security issues Alan Cox
2005-01-13 19:25                     ` Christoph Hellwig
2005-01-13 19:33                       ` Dave Jones
2005-01-13 19:35                         ` Christoph Hellwig
2005-01-13 18:55                           ` Alan Cox
2005-01-13 19:59                           ` Dave Jones
2005-01-13 19:36                     ` Marek Habersack
2005-01-13  8:23               ` Florian Weimer
2005-01-13 16:00               ` Kristofer T. Karas
2005-01-13  3:37         ` Rik van Riel
2005-01-12 19:18       ` Greg KH
2005-01-12 19:38         ` Chris Wright
2005-01-12 19:41         ` Florian Weimer
2005-01-12 23:10           ` Chris Wright
2005-01-12 19:43 ` Florian Weimer
2005-01-12 22:46   ` Chris Wright
2005-01-12 20:49 Hubert Tonneau
2005-01-13 17:29 ` Chris Wright
2005-02-27 12:38 linux

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=Pine.LNX.4.58.0501121750470.2310@ppc970.osdl.org \
    --to=torvalds@osdl.org \
    --cc=akpm@osdl.org \
    --cc=alan@lxorguk.ukuu.org.uk \
    --cc=chrisw@osdl.org \
    --cc=davej@redhat.com \
    --cc=greg@kroah.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=marcelo.tosatti@cyclades.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).