Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

zmanion :verified:

@zmanion@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange
106 Followers
79 Following
5 Posts
Joined November 07, 2022
GitHub:
https://github.com/zmanion
Twitter:
https://twitter.com/zmanion
Open post
zmanion :verified: @zmanion@infosec.exchange
· 3mo ago
Replying to
@adamshostack@infosec.exchange @pgl@infosec.exchange @jayjacobs@infosec.exchange I'm initially a fan of the explicit/implicit security policy violation, I think we'd need both: Someone could explicitly declare that they allow remote, unauthenticated access or control of a system, but everyone else may treat that as an implicit violation.
1
3
0
0
Open post
zmanion :verified: @zmanion@infosec.exchange
· 5mo ago
Replying to
@gregkh @joshbressers @wdormann @Viss so there's absolutely no middle ground? When there is clearly a bug with security impact, give the distros list a week notice (two weeks max, per their policy). If it leaks, outcome is no worse than not notifying distros. The researcher can even do it instead of the kernel. At scale (Linux!) this seems like a Pareto distribution: major distros cover disproportionally most users.
1
2
0
0
Open post
zmanion :verified: @zmanion@infosec.exchange
· 3mo ago
Replying to
@aristot73@infosec.exchange @bagder@mastodon.social @icing@chaos.social Given the history of some of the people and organizations, I'm confident at least Akrites and Lightwell will engage thoughtfully with upstream (the others maybe too, I'm not familiar with them). I'm more concerned with the technical processes at scale. We automate discovery, what about verification, reporting/notification, tracking comms and embargoes (if there are any at all), testing, reviewing, documentation (CVE, etc).
0
0
0
0
Open post
zmanion :verified: @zmanion@infosec.exchange
· 3mo ago
Replying to
@tknarr@mstdn.social @wolf480pl@mstdn.io @pgl@infosec.exchange @jayjacobs@infosec.exchange A somewhat open question: Are there just "conditions" and attackers have one perspective, environment/defenders have a different perspective? Or are there conditions that are specific to attacker vs. environment?
0
1
0
0
Open post
zmanion :verified: @zmanion@infosec.exchange
· 5mo ago
Replying to
@gregkh@social.kernel.org @joshbressers@infosec.exchange @wdormann@infosec.exchange @Viss@mastodon.social Because it exists and works better than the alternatives: telling nobody (and waiting to see who notices and when) or telling everybody all at once. If you have regulatory requirements to do or not do something, by all means, follow the regs. I'm not claiming any regs implement sound public CVD policy. Also when there is an external finder, the finder could choose to notify distros or follow other coordination paths, in addition to notifying kernel.org. (I also understand that it's not quite as simple as just dropping a message on the distros list, and I read a Qualys message explaining that they no longer use distros.)
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:31:02 UTC