1 |
On Wed, Jan 3, 2018 at 4:21 PM, Stroller <stroller@××××××××××××××××××.uk> wrote: |
2 |
> |
3 |
> If the kernel devs cared to announce when they were patching exploits then we could take each |
4 |
> one under consideration individually. But the kernel devs are secretive about kernel exploits, because |
5 |
> they know there are literally millions of systems out there on the internet with kernels months and years old. |
6 |
> |
7 |
|
8 |
I'm skeptical of that claim. I think it is more that they don't want |
9 |
to try to track which commits are associated with CVEs. I believe |
10 |
they've said as much publicly. They're not particularly secretive |
11 |
about exploits except when they're under embargo (such as at the |
12 |
present moment). |
13 |
|
14 |
-- |
15 |
Rich |