Frustrated dev drops three zero-day vulns affecting Apple iOS 15
theregister.com
theregister.com
Did you know that you can bypass the lockscreen on Linux Mint by plugging in an external monitor?
https://github.com/linuxmint/cinnamon/issues/9123
Did you know that when you use Chromium on an up-to-date Debian stable, it has over 100 unpatched security holes?
https://security-tracker.debian.org/tracker/status/release/s...
If you cannot trust Debian - whom can you trust? Any suggestions which distro takes security serious?
When did Debian become a model of trustworthiness regarding software security?
We are talking about one of the distributions applying the most patches to its repository for reasons which are often dubious and with little general oversight.
Debian is famous for being run by volunteers but it has always been kind of dodgy. We are talking about the distribution which made it's version of openssl vulnerable by breaking its random generator in order to silence a Valgrind warning.
We've also seen since then just how broken OpenSSL was generally, with Heartbleed. And why did OpenSSL have its own RNG that invoked undefined behaviour, when it could just read from /dev/random?
Moreover, in hindsight, we have a much better understanding of undefined behaviour than we used to. Undefined behaviour is not “occasionally the optimiser might bite you” but “sometimes you'll get (un)lucky in that it’ll appear to work. Don’t do it”.
https://security-tracker.debian.org/tracker/data/report https://www.debian.org/security/audit/ https://www.debian.org/doc/manuals/developers-reference/pkgs... https://wiki.debian.org/Hardening https://wiki.debian.org/Hardening/RepoAndImages https://wiki.debian.org/Hardening/Goals https://www.debian.org/intro/help
I have always wondered why "tech" companies constantly make statements on their websites such as "We take security very seriously". (Same for privacy.) There is really nothing to back them up. Its just words, no evidence. Of course the companies are all copying each others statements, but perhaps there is some science behind these words, perhaps these statements really do work. Readers actually believe them.
Its like they can make "promises" without ever actually having to deliver anything, and people actually believe they are getting some sort of "deliverable". Occasionally theres a brief "wake-up" call and then their users go back the illusion.
Being "shocked" it seems is short-lived. No doubt the "tech" companies have figured this out. I can remember when people were "shocked" about all the vulnerabilities in Windows. Those days are gone. Now there is no "shock" at all. Its expected.
Reminds me of the reports of internal communications at Facebook that showed how Sandberg and colleagues were seeking to "normalise" data breaches.
...but yes, most X11 screen lockers have this flaw.
Prevent physical access, install only ssh for external access and run Sshguard. And use Firefox as a browser.
Since it seems that Debian has decided to not patch Chromium for months now, how do I know they won't do the same for Firefox at some point? Or any other software in their repos?
I would prefer a distro which promises to keep all software in their repos secure for a certain amount of time. Even if that means having fewer packages than other distros.
[1] https://archlinux.org/packages/extra/x86_64/firefox/ [2] https://archlinux.org/packages/extra/x86_64/chromium/ (latest update was 24th sept, but there was also a 94 version published on 21st, the day of the stable release)
OpenBSD.
QubesOS, based on Xen hypervisor, provides compartmented security: a hole in an app need not provide access to anything else. You have multiple mostly long-running VMs for different roles. Hardware access is managed in VMs that do not run app code. 16GB RAM is just barely enough, and apps get no access to a GPU. But it's solid and mature. The 4.1 release, due someday, has had a lot of UX attention.
SpectrumOS is an an attempt at lighter-weight security. Based on NixOS, apps run in a minimal, temporary VM spun up just for the app, sub-second, for experience more like Docker than Virtualbox. Still very much under development. Donate to Alyssa Ross on Github to accelerate dev work.
Spectrum may be an option in the future, and I really hope it succeeds.
Code running in a toolbox container still has access to the user's home directory, and based on the bug reports on the topic, there are no plans to address this limitation.
I knew it could have access, but damn, I expected that would be optional. That's disappointing.
It's a real shame. With some additional hardening, it could achieve a nice balance between convenience and security.
SpectrumOS is built around Wayland instead.
Microphone and camera streams are, likewise, forwarded from dom0 to whatever VM you select to receive them, if any. USB gadgets you plug in, similarly, may be operated by the VM of your choice.
Slide 43 is worrying.
I'm tired of pretending like security is anything other than theater and optics at this point. You either accept humility and design transparent software, or embrace complexity and let the machine consume you. The business of building software has started shifting to the latter paradigm, and now they're paying the price for it. If we're lucky, we might see a reprieve of the late-80s within the decade, where the internet is saturated with buggy and proprietary servers ripe for the hacking.
the developers are paid
nothing to make it
Isn't Mint the second most used Linux distro or so? Shouldn't selling the default search engine alone bring in a boatload of money?On their blog they say:
Search engines who do not share the
income generated by our users, are
removed from Linux Mint and might
get their ads blocked.
https://blog.linuxmint.com/?p=1851What do you expect when you use Debian stable? Precisely people choose Debian stable because it gets no updates. (I'm only half kidding)
Chromium is a huge beast of code, should Debian maintainers be debugging and coding patches to various packages?
I think we can't expect the distro to fix the security issues in everything. It's upstream responsibility to handle their own CVE.
Perhaps Google should have one FTE for each major distro to help keep that beast of a codebase up to the standard these threads seem to expect.
It's a heavy burden to place on Debian - and I don't think it's fair to expect them to have eg Chromium and the 10-hundred other packages perfect.
Debian is fscking awesome, they are doing amazing work. Hip Hip Hooray!!
Chromium and Firefox are sort of monster code bases, though, it’s not surprising to me that distros are reluctant to change it in key ways.
Even licenses are different across packages in a repo, they normally all have a pretty clear wording how much you can hold responsible them for that (hint: no warranty, no fitness for a particular purpose).
Read it before use and think first, e.g. how that software comes to life and is managed / maintained. Debian =/= Apple.
Not sure what that has to do with licenses.
>The Register asked Apple to comment, but the brick wall did not respond.
Seems about right.
It can be hard when your job mostly consists of talking to extremely knowledgable people (such as many researchers in this field are) without yourself being at least broadly knowledgable on nearly everything technical.
Shocker
I didn't know that wasn't the default. I wouldn't really class this as an urgent security hole.