Gentoo Archives: gentoo-security

From: Joshua Brindle <method@g.o>
To: tobias@×××××××××.de
Cc: gentoo-security@l.g.o
Subject: Re: [gentoo-security] Gentoo security policy
Date: Thu, 18 Mar 2004 17:29:13
Message-Id: 4059DC58.7020104@gentoo.org
In Reply to: [gentoo-security] Gentoo security policy by Tobias Weisserth
1 Tobias Weisserth wrote:
2 > Hello everybody,
3 >
4 > There seems to be a HUGE problem with consistency in Gentoo security
5 > announcements and coordination among Gentoo maintainers.
6 >
7 > Step by step:
8 >
9 > Why does it take Gentoo that long to react to security issues?
10 >
11 > Where can I get information about who is responsible for announcing
12 > Gentoo security related issues? Is there an official Gentoo security
13 > team like Debian has? Is there a single, responsible security
14 > manager/director?
15 >
16 > Why are security announcements not handled in a consistent way? Just one
17 > example: There are at least three places where I have found Gentoo
18 > security announcements but not a single of these announcements appeared
19 > in all of these places. Rather I have to search for all of those
20 > announcements across several non-related media to collect them all. This
21 > is outrageous.
22 >
23 We have instated a new way of handling GLSA's, stay tuned
24
25 > Take the latest OpenSSL issue. Aida Escriva-Sammer posted a security
26 > announcement to full-disclosure. WHY CAN'T I FIND THIS SAME ANNOUNCEMENT
27 > IN THE OFFICIAL GENTOO ANNOUNCEMENT LISTS?!?!?! Sorry for the screaming,
28 > but if the people behind Gentoo want Gentoo to be considered a
29 > professional and productive distribution that is equal to Debian, Red
30 > Hat, SuSE and the like, then you need to handle these matters in a
31 > professional way. What you are doing right now IS NOT professional. It
32 > is dangerously careless. You are irresponsible by acting this way,
33 > endangering everybody who chooses to use Gentoo by making them believe
34 > their distribution is maintained properly because they saw some good
35 > looking security announcement at some point while they miss almost 60%
36 > of other critical issues.
37 >
38 Everyone involved is doing what they can, if you feel this isn't enough
39 feel free to join the team and help out, security is a bit underpowered
40 at the moment. I'd like to remind you that we don't get paid like
41 Redhat, SuSE and "the like".
42
43 > The latest security announcement on gentoo-announce is "Honeyd remote
44 > detection vulnerability" by Tim Yamin. This is just embarrassing. If you
45 > look at
46 > http://forums.gentoo.org/viewforum.php?f=16&sid=fbf41b023affaed791f083666ea5352b you'll see that the latest announcement there is "Linux kernel do_mremap local privilege escalation". HOW DO YOU EXPLAIN THESE INCONSISTENT ANNOUNCEMENTS?
47 >
48 > Security announcements are totally out of sync, some are never issued
49 > using the appropriate channels and most them are released hours,
50 > sometimes days after other distributors do.
51 >
52
53 We are currently not priv to the information other distributions are.
54 Although we are trying to get on the vendor-sec list we have been unable
55 to do so thus far.
56
57 > I can only advise you to take security more serious. Running any machine
58 > in a productive environment with Gentoo is totally out of the question
59 > as long as these matters are not handled in an appropriate way. So long,
60 > Gentoo is only suitable for use at home to play around unless of course
61 > every Gentoo user is his own security team.
62 >
63
64 You are treading dangerously thin here, I assure you we take security
65 seriously.
66
67 > I hope this is a wakeup call. Take care.
68 >
69
70 This wasn't anything that we didn't already know about, we already know
71 we don't have access to vulnerability reports before the 'mass public',
72 we already know we are undermanned, we already know our process is in a
73 transition state. What *you* need to know is that we are doing what we
74 can with the resources we have, and trying every day to get more
75 resources. If you don't like it you can help us, we *are* a community
76 distribution, not a commercial distribution that can pay for a full time
77 security team, nor are we a distribution with the amount of 'clout' it
78 takes to get early advirsories.
79
80 My suggestion to you is one of the following
81 1) help make the team better by participating
82 2) paying for a full time security team
83 3) deal with it.
84
85
86 Joshua Brindle
87
88 --
89 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] Gentoo security policy Jeremy Huddleston <eradicator@g.o>