Damus
alexanderkjall profile picture
alexanderkjall
@alexanderkjall
Today I have spent way too much time handling the https://copy.fail situation #copyfail

The persons who discovered it didn't notify the distribution security list, so no patched kernels was available for people to install when they released it.

But they did have time to write an exploit, and thought it was a good idea to distribute that on day one, before vendors had time to provide patches.

I'm not very impressed with xint.io, I guess it's the marketing department that runs the show.
1
penguin42 · 6w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqalqg0k33ussgfprdpuqx5e3jfvntdmd20q9jmftkkwgvtdye7fys84ueal But they say they 'Reported to Linux kernel security team' on 23rd March; shouldn't that have triggered the distros finding out?