1 |
On Thu, Mar 18, 2004 at 12:37:09PM +0100 or thereabouts, Tobias Weisserth wrote: |
2 |
> Why does it take Gentoo that long to react to security issues? |
3 |
|
4 |
Because we don't have enough people on-staff willing to help out with these |
5 |
types of issues. |
6 |
|
7 |
> Where can I get information about who is responsible for announcing |
8 |
> Gentoo security related issues? Is there an official Gentoo security |
9 |
> team like Debian has? Is there a single, responsible security |
10 |
> manager/director? |
11 |
|
12 |
Myself and Joshua Brindle (method) have recently assumed repsonsibility for |
13 |
the security project. |
14 |
|
15 |
> Why are security announcements not handled in a consistent way? Just one |
16 |
> example: There are at least three places where I have found Gentoo |
17 |
> security announcements but not a single of these announcements appeared |
18 |
> in all of these places. Rather I have to search for all of those |
19 |
> announcements across several non-related media to collect them all. This |
20 |
> is outrageous. |
21 |
|
22 |
At least recently (say the last 5-6 GLSAs), everything should have been |
23 |
consistent. |
24 |
|
25 |
> Take the latest OpenSSL issue. Aida Escriva-Sammer posted a security |
26 |
> announcement to full-disclosure. WHY CAN'T I FIND THIS SAME ANNOUNCEMENT |
27 |
> IN THE OFFICIAL GENTOO ANNOUNCEMENT LISTS?!?!?! Sorry for the screaming, |
28 |
> but if the people behind Gentoo want Gentoo to be considered a |
29 |
> professional and productive distribution that is equal to Debian, Red |
30 |
> Hat, SuSE and the like, then you need to handle these matters in a |
31 |
> professional way. What you are doing right now IS NOT professional. It |
32 |
> is dangerously careless. You are irresponsible by acting this way, |
33 |
> endangering everybody who chooses to use Gentoo by making them believe |
34 |
> their distribution is maintained properly because they saw some good |
35 |
> looking security announcement at some point while they miss almost 60% |
36 |
> of other critical issues. |
37 |
|
38 |
Screaming will get you nowhere except directed to my bit-bucket. If you |
39 |
have ideas on how to improve things and are willing to back that up with |
40 |
investing your own time and effort as well, then great. We can always use |
41 |
more help. |
42 |
|
43 |
|
44 |
> The latest security announcement on gentoo-announce is "Honeyd remote |
45 |
> detection vulnerability" by Tim Yamin. This is just embarrassing. If you |
46 |
> look at |
47 |
> http://forums.gentoo.org/viewforum.php?f=16&sid=fbf41b023affaed791f083666ea5352b you'll see that the latest announcement there is "Linux kernel do_mremap local privilege escalation". HOW DO YOU EXPLAIN THESE INCONSISTENT ANNOUNCEMENTS? |
48 |
|
49 |
I explain them by saying your facts are incorrect. |
50 |
|
51 |
> Security announcements are totally out of sync, some are never issued |
52 |
> using the appropriate channels and most them are released hours, |
53 |
> sometimes days after other distributors do. |
54 |
|
55 |
So put your money (or, in this case, your time) where your mouth is and |
56 |
help out. |
57 |
|
58 |
> I can only advise you to take security more serious. Running any machine |
59 |
> in a productive environment with Gentoo is totally out of the question |
60 |
> as long as these matters are not handled in an appropriate way. So long, |
61 |
> Gentoo is only suitable for use at home to play around unless of course |
62 |
> every Gentoo user is his own security team. |
63 |
> |
64 |
> I hope this is a wakeup call. Take care. |
65 |
|
66 |
We're a volunteer organization and we depend on people to volunteer their |
67 |
time. As I mentioned, we're short-staffed at the moment. Want to help? |
68 |
Drop me an email. |
69 |
|
70 |
--kurt |