437 karma · joined December 15, 2011
I haven't heard that before. Care to elaborate what we do that makes you believe we don't take security seriously?
Mozilla actually removed the certs from their trust store in February 2021: https://hg.mozilla.org/projects/nss/rev/9718a34c84429b1e5dc6...
Debian and Ubuntu had jumped the gun by a few weeks and there were certificates still being used that had not been renewed yet, so we had to revert temporarily.
Mozilla had used the CKA_NSS_SERVER_DISTRUST_AFTER tag with a date to specify newer certs issued by that CA were not valid, but as the article above states, the crypto libraries being used in Linux don't support that kind of thing.
The "needs triage" you're seeing for Ubuntu 16.10 is for the "linux-goldfish" and "linux-flo" kernel packages for specific android devices.
https://bugs.launchpad.net/ubuntu/+source/grub2/+bug/1443735
http://www.openwall.com/lists/oss-security/2014/09/25/10
I am building bash updates for Ubuntu containing the proposed fix here and will publish them once the fix has been made official:
https://launchpad.net/~ubuntu-security-proposed/+archive/ubu...
How is this Hacker News worthy?