/srv/irclogs.ubuntu.com/2015/01/28/#ubuntu-nz.txt

GOuch, glibc GHOST doesn't sound very nice... http://www.openwall.com/lists/oss-security/2015/01/27/900:00
ollyit's already fixed in upstream glibc at least00:16
ollynot looked at ubuntu, but debian testing and unstable weren't vulnerable00:16
Gbasically all the LTS' from <'13 because it wasn't backported as security until today00:17
ollythe email from the discoverers is an interesting read00:18
Gyeah, I just saw an interesting tweet too:  'The embargo on CVE-2015-0235 was broken by a ham-fisted PR engaged by the firm who discovered it. So CVEs now come with cute names AND PR.' https://twitter.com/matthewbloch/status/56021620875120230700:23
* olly was wondering earlier what the indirect benefits from finding a high-profile vulnerability are00:23
Gwell I guess cute name + PR dept answers it... Trademark the cute name, be the only company that can sell the "<cute name> Detection Tool"00:24
ollyi suspect the real benefits are from reputation - if you're looking for someone to audit some code, going for the guys who found X, Y and Z is an obvious choice00:25
Gthat too00:25
Gbetter to list a bunch of cute names than random CVE numbers that a lot of people won't make the connection too00:26
ollyparallels to FOSS development - if you want some work doing related to a project, you're likely to hire the people who put a lot of work into it00:26
ollytrue00:26
ollyit's kind of a nice eco-system - there's a motivation for people to put work into finding vulnerabilities without direct renumeration00:28
G+ the fact that for the major online-impacting bugs that have cute names, the media are using on them.  So even 'muggles' know abotu Heartbleed for instance.   "Hey #non-up-with-tech-boss, CompanyX can audit our code for $x, they were the ones that found Heartbleed"  does sound better than "that found CVE-2014-...."00:28
ollyremuneration even00:28
Gso yeah, you are right, PR part is likely so they put info packets together for justification of paying that company for other security related services00:30
ollyquite possibly they have a PR company anyway00:31
ollymany companies do00:31
ollydoes trusty mount /tmp noexec?01:38
mwhudsonnot sure, utopic does01:51
ollythanks02:13
ibeardsleemorning19:05

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!