1 |
Tobias Weisserth wrote: |
2 |
> Hello everybody, |
3 |
> |
4 |
> There seems to be a HUGE problem with consistency in Gentoo security |
5 |
> announcements and coordination among Gentoo maintainers. |
6 |
> |
7 |
> Step by step: |
8 |
> |
9 |
> Why does it take Gentoo that long to react to security issues? |
10 |
> |
11 |
> Where can I get information about who is responsible for announcing |
12 |
> Gentoo security related issues? Is there an official Gentoo security |
13 |
> team like Debian has? Is there a single, responsible security |
14 |
> manager/director? |
15 |
> |
16 |
> Why are security announcements not handled in a consistent way? Just one |
17 |
> example: There are at least three places where I have found Gentoo |
18 |
> security announcements but not a single of these announcements appeared |
19 |
> in all of these places. Rather I have to search for all of those |
20 |
> announcements across several non-related media to collect them all. This |
21 |
> is outrageous. |
22 |
> |
23 |
We have instated a new way of handling GLSA's, stay tuned |
24 |
|
25 |
> Take the latest OpenSSL issue. Aida Escriva-Sammer posted a security |
26 |
> announcement to full-disclosure. WHY CAN'T I FIND THIS SAME ANNOUNCEMENT |
27 |
> IN THE OFFICIAL GENTOO ANNOUNCEMENT LISTS?!?!?! Sorry for the screaming, |
28 |
> but if the people behind Gentoo want Gentoo to be considered a |
29 |
> professional and productive distribution that is equal to Debian, Red |
30 |
> Hat, SuSE and the like, then you need to handle these matters in a |
31 |
> professional way. What you are doing right now IS NOT professional. It |
32 |
> is dangerously careless. You are irresponsible by acting this way, |
33 |
> endangering everybody who chooses to use Gentoo by making them believe |
34 |
> their distribution is maintained properly because they saw some good |
35 |
> looking security announcement at some point while they miss almost 60% |
36 |
> of other critical issues. |
37 |
> |
38 |
Everyone involved is doing what they can, if you feel this isn't enough |
39 |
feel free to join the team and help out, security is a bit underpowered |
40 |
at the moment. I'd like to remind you that we don't get paid like |
41 |
Redhat, SuSE and "the like". |
42 |
|
43 |
> The latest security announcement on gentoo-announce is "Honeyd remote |
44 |
> detection vulnerability" by Tim Yamin. This is just embarrassing. If you |
45 |
> look at |
46 |
> http://forums.gentoo.org/viewforum.php?f=16&sid=fbf41b023affaed791f083666ea5352b you'll see that the latest announcement there is "Linux kernel do_mremap local privilege escalation". HOW DO YOU EXPLAIN THESE INCONSISTENT ANNOUNCEMENTS? |
47 |
> |
48 |
> Security announcements are totally out of sync, some are never issued |
49 |
> using the appropriate channels and most them are released hours, |
50 |
> sometimes days after other distributors do. |
51 |
> |
52 |
|
53 |
We are currently not priv to the information other distributions are. |
54 |
Although we are trying to get on the vendor-sec list we have been unable |
55 |
to do so thus far. |
56 |
|
57 |
> I can only advise you to take security more serious. Running any machine |
58 |
> in a productive environment with Gentoo is totally out of the question |
59 |
> as long as these matters are not handled in an appropriate way. So long, |
60 |
> Gentoo is only suitable for use at home to play around unless of course |
61 |
> every Gentoo user is his own security team. |
62 |
> |
63 |
|
64 |
You are treading dangerously thin here, I assure you we take security |
65 |
seriously. |
66 |
|
67 |
> I hope this is a wakeup call. Take care. |
68 |
> |
69 |
|
70 |
This wasn't anything that we didn't already know about, we already know |
71 |
we don't have access to vulnerability reports before the 'mass public', |
72 |
we already know we are undermanned, we already know our process is in a |
73 |
transition state. What *you* need to know is that we are doing what we |
74 |
can with the resources we have, and trying every day to get more |
75 |
resources. If you don't like it you can help us, we *are* a community |
76 |
distribution, not a commercial distribution that can pay for a full time |
77 |
security team, nor are we a distribution with the amount of 'clout' it |
78 |
takes to get early advirsories. |
79 |
|
80 |
My suggestion to you is one of the following |
81 |
1) help make the team better by participating |
82 |
2) paying for a full time security team |
83 |
3) deal with it. |
84 |
|
85 |
|
86 |
Joshua Brindle |
87 |
|
88 |
-- |
89 |
gentoo-security@g.o mailing list |