TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Linus Torvalds Talks Linux Security at LinuxCon

137 pointsby kerckerover 9 years ago

6 comments

riskableover 9 years ago
Why do I keep seeing Heartbleed and Shellshock mentioned in articles specifically about Linux security? Those two vulnerabilities had nothing to do with Linux.<p>Software using OpenSSL or bash on <i>any</i> platform were vulnerable. That includes Macs and Windows.<p>Linux is extremely popular for servers and embedded systems where OpenSSL and bash are common but bringing them up every time &quot;security + Linux&quot; are discussed is a bit like talking about tires that blow out whenever the topic of logistics comes up.
评论 #10522297 未加载
评论 #10521901 未加载
评论 #10522089 未加载
评论 #10522918 未加载
评论 #10522723 未加载
mrweaselover 9 years ago
&gt;Most of the security issues we&#x27;ve had in the kernel have been just completely stupid bugs...<p>Wouldn&#x27;t that be an argument to be more stringent in reviewing and auditing the kernel code? I don&#x27;t know to which extend they already do audits, but if you find a bug of a certain type, maybe consider combing the tree for other instances of that type of bug. I believe that&#x27;s the approach OpenBSD has taken.
评论 #10522482 未加载
评论 #10521568 未加载
Gravitylossover 9 years ago
(by the way the article is dated August 2015)<p>I love the tone here. Not promising the moon.<p>Everybody knows there will be bugs. In general it&#x27;s just that dance that you have to do around that, that you can&#x27;t admit it.<p>Same about planning ten years to the future. Maybe you could give scenarios.<p>I guess he&#x27;s expecting quite a lot from the audience.
评论 #10520861 未加载
fulafelover 9 years ago
I propose a corollary to the &quot;bugs are shallow&quot; quote: &quot;Given enough code output, all programmers are stupid&quot;
teamhappyover 9 years ago
Here&#x27;s the video: <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=5xKXHavHJ7U" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=5xKXHavHJ7U</a>
ak217over 9 years ago
Related to the recent interview notes by Brad Spender: <a href="https:&#x2F;&#x2F;grsecurity.net&#x2F;~spender&#x2F;interview_notes.txt" rel="nofollow">https:&#x2F;&#x2F;grsecurity.net&#x2F;~spender&#x2F;interview_notes.txt</a><p>IMO it&#x27;s scary to hear Linus say that &quot;security is just stupid bugs&quot; and that he doesn&#x27;t think about containers much (container&#x2F;namespace security and functionality is a big and quickly emerging part of the kernel security landscape). Call it a lack of vision or whatever, but I think he should be doing more to architect for security and to recruit, place and reward talented people into security lead positions in the kernel community.
评论 #10520900 未加载
评论 #10521431 未加载
评论 #10522795 未加载
评论 #10520783 未加载
评论 #10521079 未加载
评论 #10520629 未加载
评论 #10520731 未加载