@aristot73@infosec.exchange @wdormann@infosec.exchange This whole article is laughable.
Historically a lot of vulnerability reporting and interactions happened between researchers and companies.For Linux the 'company' is LF that Greg is part of. He is not a poor underfunded hobbyist.The researchers have an incentive also.
If they are looking for prestige, they want to find critical vulnerabilities.Greg has an incentive too. If he is looking for prestige it is in his interest to withhold information on critical vulnerabilities, paint himself as the messiah of Linux security, and everyone else as incompetents.
GKH:Why is linux-distros somehow "special" enough to get these types of announcements and not everyone else?Yeah, well, they subscribed to that security list that is supposed to announce things like that. That way they made it clear that they care.
GKH:As I have said for quite some time now, all early-disclosure lists are leaks, otherwise why would your government allow them to be in existence?He forgot to mention that when people are shown to be source of leaks they are kicked from the list. Certainly not perfect but disclosing to the list is far from the same as making the vulnerability public.
GKH has been also heard on multiple occasions dunking on distributions maintaining their own kernels as opposed to using stable Linux branches.
From the article againAnyway, companies have more on the hook when there is a vulnerability. They don’t get to cut a release and they’re done. They will need to talk to customers, run some support sessions.Yet Debian which is a community distribution, not a company, using GKH's promoted stable tree, not their own got nothing. No notification, no fix. As it happens Greg did not backport the fix to the stable trees himself, he left that to the distributions. Yes, those distributions that nobody notified of the importance of this vulnerability. So no fix for anybody who is running any 'stable' Linux distribution. :bunhdgoogly: