It's listed as medium severity and appears to require the hacker to already have terminal access to the system. It's also already patched and there's a quick and easy workaround if your distro doesn't have the fix yet.
I think that the OP(the article author) is not looking at this the right way. Like yea it sucks another exploit is found, but it's not like if it wasn't found it doesn't exist.
I think its much better to have them published and fixed then to live in blissful ignorance when someone could be exploiting it in the wild.
It is more important than ever to introduce geo-ip conditional access on your network(s). That way you limit your attack surface by a significant margin.
“the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools.”
Times change. I’d say if slop finds exploitable bugs, it’s not slop. And if your 30 year old method of doing something doesn’t work anymore, take a few minutes to make a better solution. 🤷♂️
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
But it's not the same person reporting the same bug multiple time but rather a new tool enabling multiple people to discover that same bug at the same time.
Not reporting it because "someone else probably will" is a sociopsychological phenomenon called diffusion of responsibility.
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven’t been spotted, but there’s a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
All found with some AI assistance and a lot of human expertise sifting through the hallucinations to work out the actually exploutable stuff. And the AI bug apocalypse has turned up a whole 4 bugs serious bugs so far, ooo scary. I'm still waiting to be impressed.
And that (obviously) is the low hanging fruit. We end up with a more secure kernel, and these filter in at a manageable rate and the bar raises. Pretty damn good scenario IMO.
I don’t have any concern for votes because I do not display them. Just because you, and several other alt accounts can push a down button doesn’t mean that will ever affect me – because I can’t see it. However, according to you – every single down voted comment is a bad comment regardless of its content. So according to you, if I get downloaded for complaining about, let’s say murdering innocent children, then I must be a bad person. Your logic doesn’t work out buddy.
This isn't an example of a broken clock being right twice a day. Torvalds is complaining that his inbox is flooded with bug reports because everyone's monkey suddenly started outputting Shakespeare.
Torvalds is complaining that his inbox is flooded with endlessly duplicated bug reports because everyone’s monkey suddenly started outputting low-grade, plagiarized, relentlessly repeated "Shakespeare"
54 Comments
kescusay@lemmy.world · 116 pts · 88d
It's listed as medium severity and appears to require the hacker to already have terminal access to the system. It's also already patched and there's a quick and easy workaround if your distro doesn't have the fix yet.
Pika@sh.itjust.works · 110 pts · 88d
I think that the OP(the article author) is not looking at this the right way. Like yea it sucks another exploit is found, but it's not like if it wasn't found it doesn't exist.
I think its much better to have them published and fixed then to live in blissful ignorance when someone could be exploiting it in the wild.
9point6@lemmy.world · 62 pts · 88d
Oh FFS, the rest of my life is doomed to be spent updating software
db2@lemmy.world · 75 pts · 88d
🌏🧑🚀🔫🧑🚀
wltr@discuss.tchncs.de · 17 pts · 88d
Always has been!
LeapSecond@lemmy.zip · 51 pts · 88d
But careful not to update too fast and fall on the supply chain attack of the week.
albbi@piefed.ca · 5 pts · 88d
Pretty sure that was in the bible.
Proverbs 25:16 - If you find honey, eat just enough - too much of it, and you will vomit.
Could update that to be: If you find updates, apply them - too soon though, and you will vomit your credentials.
corsicanguppy@lemmy.ca · 1 pts · 88d
That's difficult. Openssh is coded in C, not js.
NGC2346@sh.itjust.works · 10 pts · 87d
It is more important than ever to introduce geo-ip conditional access on your network(s). That way you limit your attack surface by a significant margin.
9point6@lemmy.world · 4 pts · 87d
My personal stuff 100%
For work? No such choice (apart from the obvious ones)
NGC2346@sh.itjust.works · 1 pts · 87d
Your work most likely already has conditional access through MS Entra
9point6@lemmy.world · 1 pts · 87d
Not a Microsoft shop, but yes they have a pretty extensive IDS for anything public facing, another company to handle internal Auth
MagicShel@lemmy.zip · 4 pts · 88d
That's what we call job security, I suppose.
JaymesRS@piefed.world · 11 pts · 88d
Oh good. Nothing too serious, then.
meowmeow@quokk.au · -96 pts · 88d
All found with AI, you haters. And Linus complains the mailing list is too busy… with bugs.
Sickday@kbin.earth · 67 pts · 88d
with duplicate bug reports.
meowmeow@quokk.au · -58 pts · 88d
Mailing lists, it turns out, is a bad tool.
Haquer@lemmy.today · 38 pts · 88d
It's worked for over 30 years, until the slop generators turned on.
Dunno duder
meowmeow@quokk.au · -37 pts · 88d
Times change. I’d say if slop finds exploitable bugs, it’s not slop. And if your 30 year old method of doing something doesn’t work anymore, take a few minutes to make a better solution. 🤷♂️
AnarchistArtificer@slrpnk.net · 25 pts · 88d
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Duplicates don't add anything to the conversation
Iconoclast@feddit.uk · -1 pts · 87d
But it's not the same person reporting the same bug multiple time but rather a new tool enabling multiple people to discover that same bug at the same time.
Not reporting it because "someone else probably will" is a sociopsychological phenomenon called diffusion of responsibility.
vulpivia@lemmy.dbzer0.com · 4 pts · 87d
It's not about "someone else probably will", it's about "someone else already has". No one is advocating for diffusion of responsibility.
AnarchistArtificer@slrpnk.net · 22 pts · 88d
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Duplicates don't add anything to the conversation
AnarchistArtificer@slrpnk.net · 20 pts · 88d
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Duplicates don't add anything to the conversation
AnarchistArtificer@slrpnk.net · 19 pts · 88d
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Duplicates don't add anything to the conversation
demonsword@lemmy.world · 5 pts · 87d
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven’t been spotted, but there’s a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Duplicates don’t add anything to the conversation
towerful@programming.dev · 3 pts · 87d
Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven't been spotted, but there's a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.
Duplicates don't add anything to the conversation
Mondez@lemdro.id · 47 pts · 88d
All found with some AI assistance and a lot of human expertise sifting through the hallucinations to work out the actually exploutable stuff. And the AI bug apocalypse has turned up a whole 4 bugs serious bugs so far, ooo scary. I'm still waiting to be impressed.
MalReynolds@slrpnk.net · 14 pts · 88d
And that (obviously) is the low hanging fruit. We end up with a more secure kernel, and these filter in at a manageable rate and the bar raises. Pretty damn good scenario IMO.
Closed source is going to have a much worse time.
horn_e4_beaver@discuss.tchncs.de · 10 pts · 88d
It's funny how almost all the AI services out there seem to have forgotten to publish any precision/recall stats.
bigbangdangler@reddthat.com · 2 pts · 88d
No no, real numbers would hurt the bottom line. AI relies on great expectations and overly trusting techbros.
meowmeow@quokk.au · -39 pts · 88d
No one thinks impressing you is a goal.
EncryptKeeper@lemmy.world · 25 pts · 88d
Easy there Pickle Rick you might cut yourself on that edge lol
meowmeow@quokk.au · -29 pts · 88d
It got your attention ;)
greyscale@lemmy.grey.ooo · 10 pts · 88d
Yes, the goal is to impress easily distracted rubes.
Which it has clearly done.
kescusay@lemmy.world · 29 pts · 88d
Why are you like this?
meowmeow@quokk.au · -32 pts · 88d
Lemmy has driven me to be an angry person who likes to point out how hypocritical people are.
db2@lemmy.world · 37 pts · 88d
You should try not sucking at it though.
meowmeow@quokk.au · -26 pts · 88d
Sucking is relative. I would have to respect you for that to be an insult.
greyscale@lemmy.grey.ooo · 11 pts · 88d
You're getting ratio'd pretty hard (by lemmy standards)
You don't have anyone here's respect, so why would they care for yours?
meowmeow@quokk.au · -19 pts · 88d
I don’t have any concern for votes because I do not display them. Just because you, and several other alt accounts can push a down button doesn’t mean that will ever affect me – because I can’t see it. However, according to you – every single down voted comment is a bad comment regardless of its content. So according to you, if I get downloaded for complaining about, let’s say murdering innocent children, then I must be a bad person. Your logic doesn’t work out buddy.
db2@lemmy.world · 12 pts · 88d
greyscale@lemmy.grey.ooo · 9 pts · 88d
I didn't read your message.
Edit: Because you seem a little thick: Because I don't respect you.
KryptonNerd@slrpnk.net · 4 pts · 87d
Please go step outside and touch grass
mnemonicmonkeys@sh.itjust.works · 1 pts · 88d
Sounds like a skill issue on your part. Cope harder.
horn_e4_beaver@discuss.tchncs.de · 5 pts · 88d
All found with my infinite set of monkeys on typewriters.
magic_smoke@lemmy.blahaj.zone · 1 pts · 88d
Iconoclast@feddit.uk · 0 pts · 87d
This isn't an example of a broken clock being right twice a day. Torvalds is complaining that his inbox is flooded with bug reports because everyone's monkey suddenly started outputting Shakespeare.
demonsword@lemmy.world · 1 pts · 87d
Jhex@lemmy.world · 5 pts · 88d
two week old account seemingly dedicated to peddle AI… blocked