• Pika@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    90
    arrow-down
    1
    ·
    24 hours ago

    I think that the OP(the article author) is not looking at this the right way. Like yea it sucks another exploit is found, but it’s not like if it wasn’t found it doesn’t exist.

    I think its much better to have them published and fixed then to live in blissful ignorance when someone could be exploiting it in the wild.

  • kescusay@lemmy.world
    link
    fedilink
    English
    arrow-up
    105
    arrow-down
    1
    ·
    1 day ago

    It’s listed as medium severity and appears to require the hacker to already have terminal access to the system. It’s also already patched and there’s a quick and easy workaround if your distro doesn’t have the fix yet.

    • NGC2346@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      5
      ·
      2 hours ago

      It is more important than ever to introduce geo-ip conditional access on your network(s). That way you limit your attack surface by a significant margin.

      • 9point6@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        2 hours ago

        My personal stuff 100%

        For work? No such choice (apart from the obvious ones)

      • Albbi@piefed.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        22 hours ago

        Pretty sure that was in the bible.

        Proverbs 25:16 - If you find honey, eat just enough - too much of it, and you will vomit.

        Could update that to be: If you find updates, apply them - too soon though, and you will vomit your credentials.

  • meowmeow@quokk.au
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    100
    ·
    1 day ago

    All found with AI, you haters. And Linus complains the mailing list is too busy… with bugs.

    • Sickday@kbin.earth
      link
      fedilink
      arrow-up
      61
      ·
      1 day ago

      too busy… with bugs.

      with duplicate bug reports.

      “the continued flood of AI reports has basically made the security list almost entirely unmanageable, with enormous duplication due to different people finding the same things with the same tools.”

        • Haquer@lemmy.today
          link
          fedilink
          English
          arrow-up
          34
          ·
          1 day ago

          It’s worked for over 30 years, until the slop generators turned on.

          Dunno duder

          • meowmeow@quokk.au
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            38
            ·
            24 hours ago

            Times change. I’d say if slop finds exploitable bugs, it’s not slop. And if your 30 year old method of doing something doesn’t work anymore, take a few minutes to make a better solution. 🤷‍♂️

            • towerful@programming.dev
              link
              fedilink
              English
              arrow-up
              1
              ·
              31 minutes ago

              Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven’t been spotted, but there’s a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.

              Duplicates don’t add anything to the conversation

            • demonsword@lemmy.world
              link
              fedilink
              English
              arrow-up
              4
              ·
              2 hours ago

              Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven’t been spotted, but there’s a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.

              Duplicates don’t add anything to the conversation

            • AnarchistArtificer@slrpnk.net
              link
              fedilink
              English
              arrow-up
              23
              ·
              20 hours ago

              Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven’t been spotted, but there’s a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.

              Duplicates don’t add anything to the conversation

              • Iconoclast@feddit.uk
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                1
                ·
                4 hours ago

                Duplicates don’t add anything to the conversation

                But it’s not the same person reporting the same bug multiple time but rather a new tool enabling multiple people to discover that same bug at the same time.

                Not reporting it because “someone else probably will” is a sociopsychological phenomenon called diffusion of responsibility.

                • vulpivia@lemmy.dbzer0.com
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  33 minutes ago

                  It’s not about “someone else probably will”, it’s about “someone else already has”. No one is advocating for diffusion of responsibility.

            • AnarchistArtificer@slrpnk.net
              link
              fedilink
              English
              arrow-up
              19
              ·
              20 hours ago

              Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven’t been spotted, but there’s a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.

              Duplicates don’t add anything to the conversation

            • AnarchistArtificer@slrpnk.net
              link
              fedilink
              English
              arrow-up
              17
              ·
              20 hours ago

              Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven’t been spotted, but there’s a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.

              Duplicates don’t add anything to the conversation

            • AnarchistArtificer@slrpnk.net
              link
              fedilink
              English
              arrow-up
              17
              ·
              20 hours ago

              Yes but the problem is that people keep submitting the same bug again and again and again. Some bugs exist because they haven’t been spotted, but there’s a heckton of bugs that are known about, but no-one has been able to put forward a fix for them yet. Overloading people with duplicate reports just means that they have less time and brainspace available to spend on fixing bugs.

              Duplicates don’t add anything to the conversation

    • richmondez@lemdro.id
      link
      fedilink
      English
      arrow-up
      45
      ·
      1 day ago

      All found with some AI assistance and a lot of human expertise sifting through the hallucinations to work out the actually exploutable stuff. And the AI bug apocalypse has turned up a whole 4 bugs serious bugs so far, ooo scary. I’m still waiting to be impressed.

      • meowmeow@quokk.au
        link
        fedilink
        English
        arrow-up
        9
        arrow-down
        41
        ·
        1 day ago

        Lemmy has driven me to be an angry person who likes to point out how hypocritical people are.

          • meowmeow@quokk.au
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            29
            ·
            1 day ago

            Sucking is relative. I would have to respect you for that to be an insult.

            • greyscale@lemmy.grey.ooo
              link
              fedilink
              English
              arrow-up
              10
              ·
              1 day ago

              You’re getting ratio’d pretty hard (by lemmy standards)

              You don’t have anyone here’s respect, so why would they care for yours?

              • meowmeow@quokk.au
                link
                fedilink
                English
                arrow-up
                2
                arrow-down
                21
                ·
                1 day ago

                I don’t have any concern for votes because I do not display them. Just because you, and several other alt accounts can push a down button doesn’t mean that will ever affect me – because I can’t see it. However, according to you – every single down voted comment is a bad comment regardless of its content. So according to you, if I get downloaded for complaining about, let’s say murdering innocent children, then I must be a bad person. Your logic doesn’t work out buddy.

    • Jhex@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      1
      ·
      20 hours ago

      two week old account seemingly dedicated to peddle AI… blocked

    • horn_e4_beaver@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      2
      ·
      23 hours ago

      All found with AI, you haters. And Linus complains the mailing list is too busy… with bugs.

      All found with my infinite set of monkeys on typewriters.

      • Iconoclast@feddit.uk
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        4 hours ago

        This isn’t an example of a broken clock being right twice a day. Torvalds is complaining that his inbox is flooded with bug reports because everyone’s monkey suddenly started outputting Shakespeare.

        • demonsword@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          2 hours ago

          Torvalds is complaining that his inbox is flooded with endlessly duplicated bug reports because everyone’s monkey suddenly started outputting low-grade, plagiarized, relentlessly repeated “Shakespeare”