Stories
Slash Boxes
Comments

SoylentNews is people

posted by cmn32480 on Wednesday November 11 2015, @09:17PM   Printer-friendly
from the your-code-looks-like-swiss-cheese dept.

The Washington Post published an article today which describes the ongoing tension between the security community and Linux kernel developers. This has been roundly denounced as FUD, with Rob Graham going so far as to claim that nobody ever attacks the kernel.

Unfortunately he's entirely and demonstrably wrong, it's not FUD and the state of security in the kernel is currently far short of where it should be.

[Here is] an example. Recent versions of Android use SELinux to confine applications. Even if you have full control over an application running on Android, the SELinux rules make it very difficult to do anything especially user-hostile. Hacking Team, the GPL-violating Italian company who sells surveillance software to human rights abusers, found that this impeded their ability to drop their spyware onto targets' devices. So they took advantage of the fact that many Android devices shipped a kernel with a flawed copy_from_user() implementation that allowed them to copy arbitrary userspace data over arbitrary kernel code, thus allowing them to disable SELinux.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0, Flamebait) by Anonymous Coward on Wednesday November 11 2015, @09:51PM

    by Anonymous Coward on Wednesday November 11 2015, @09:51PM (#261933)

    Matthew Garrett? Is he still running his SJWed fork of Linux on Github?

    Starting Score:    0  points
    Moderation   0  
       Offtopic=1, Flamebait=1, Insightful=1, Informative=1, Total=4
    Extra 'Flamebait' Modifier   0  

    Total Score:   0  
  • (Score: 0, Offtopic) by linkdude64 on Wednesday November 11 2015, @10:11PM

    by linkdude64 (5482) on Wednesday November 11 2015, @10:11PM (#261939)

    While I share your disapproval of the Social Justice Warrior, it is important to remember that specific, open-minded, and logical articulation of ideas is what separates thinkers from zealots.

    "Fuck this SJW," no matter how agreeable the statement may be, would be more widely accepted and respectable were you to include and explain the supporting evidence needed to validate such a strong statement.

    • (Score: 2, Informative) by Tork on Wednesday November 11 2015, @10:20PM

      by Tork (3914) Subscriber Badge on Wednesday November 11 2015, @10:20PM (#261944)
      In other words, the term SJW is shorthand for: "I'm angry, ignorant, and my post lacks content."
      --
      🏳️‍🌈 Proud Ally 🏳️‍🌈
      • (Score: 4, Insightful) by linkdude64 on Wednesday November 11 2015, @11:03PM

        by linkdude64 (5482) on Wednesday November 11 2015, @11:03PM (#261963)

        Certainly not any moreso than the majority of comments "SJWs" make about most of their gripes. Extremism is the problem here, not a particular ideology; rejecting any statement outright based on buzzwords alone is hasty, IMO. Either way, this is offtopic.

        • (Score: 1, Offtopic) by Tork on Wednesday November 11 2015, @11:41PM

          by Tork (3914) Subscriber Badge on Wednesday November 11 2015, @11:41PM (#261976)
          The term SJW is applied so broadly that your statement is not true, that's why I said what I did about lacking content. I do agree that I went way off-topic.
          --
          🏳️‍🌈 Proud Ally 🏳️‍🌈
          • (Score: -1, Flamebait) by Anonymous Coward on Wednesday November 11 2015, @11:53PM

            by Anonymous Coward on Wednesday November 11 2015, @11:53PM (#261984)

            Fuck off. Go suck on some transgendered freak's plastic dildo dick.

    • (Score: 2, Funny) by Anonymous Coward on Wednesday November 11 2015, @10:25PM

      by Anonymous Coward on Wednesday November 11 2015, @10:25PM (#261947)

      Why do you presume I care about validation from the rest of the world? mjg is a stupid SJW who attention-whored out his github fork of the kernel and then after about a dozen commits it went dead and is now more than a month behind mainline. Great success!

    • (Score: 2, Insightful) by Anonymous Coward on Wednesday November 11 2015, @11:11PM

      by Anonymous Coward on Wednesday November 11 2015, @11:11PM (#261966)

      The guy had not deigned to include *any* evidence for this tale. Expects his words to be taken on faith.
      Ergo - see subject.

      The Internet is overfull of tall tales, and of spinners of such. Any faith I had, is long ago spent several times over; evidence must be presented. When a vulnerability is spoken about - there should be the CVE at the very leastest least. Or the only purpose of the words is plain unvarnished FUD.

      • (Score: 1, Flamebait) by Anonymous Coward on Wednesday November 11 2015, @11:20PM

        by Anonymous Coward on Wednesday November 11 2015, @11:20PM (#261972)

        How dare you. When an SJW states something is fact then it is fact. Do not try to use your white, cisgender priviledge to question them.