Rocksolid Light

News from da outaworlds

mail  files  register  groups  login

Message-ID:  

The Public is merely a multiplied "me." -- Mark Twain


comp / comp.os.linux.advocacy / Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealed on October 6th

SubjectAuthor
* 9.9/10 security vulnerability affecting Linux (and others) set to be revealed onCrudeSausage
+- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeDFS
`* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeRonB
 +* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeCrudeSausage
 |+- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeRonB
 |`* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeRonB
 | `* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeCrudeSausage
 |  +- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be reveale-hh
 |  +* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 |  |+* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeChris Ahlstrom
 |  ||`* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 |  || +* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeRonB
 |  || |`* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 |  || | `* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeRonB
 |  || |  `- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 |  || `* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeChris Ahlstrom
 |  ||  `- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 |  |`* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeRonB
 |  | `* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 |  |  `- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeChris Ahlstrom
 |  `* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeRonB
 |   `* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeCrudeSausage
 |    `* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 |     +* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeChris Ahlstrom
 |     |`- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 |     `* Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeCrudeSausage
 |      +- Re: security vulnerability affecting Linux (and others) set to be revealed on OcPhillip Frabott
 |      +- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeRonB
 |      `- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealerbowman
 `- Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealeStéphane CARPENTIER

Pages:12
Subject: Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealed on October 6th
From: rbowman
Newsgroups: comp.os.linux.advocacy
Date: Sun, 29 Sep 2024 02:48 UTC
References: 1 2 3 4 5 6 7 8 9
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: bowman@montana.com (rbowman)
Newsgroups: comp.os.linux.advocacy
Subject: Re: 9.9/10 security vulnerability affecting Linux (and others) set to
be revealed on October 6th
Date: 29 Sep 2024 02:48:15 GMT
Lines: 42
Message-ID: <llrtfeFqbh9U1@mid.individual.net>
References: <2O1JO.214184$FzW1.145017@fx14.iad> <vd2mdm$1ue8$1@dont-email.me>
<alcJO.194436$kxD8.182014@fx11.iad> <vd5bkk$jdi1$1@dont-email.me>
<cJxJO.172505$1m96.122070@fx15.iad> <vd7dt1$tcgq$1@dont-email.me>
<L5SJO.109033$WtV9.49623@fx10.iad> <llr1knFm711U2@mid.individual.net>
<vd9qtf$1d21b$5@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net 4Gc2efWgMRZI0RBUeNK21AhmXyEgNp6/d2lAJthozeTdhRVfP8
Cancel-Lock: sha1:ycqdFvO3j07LcZgb1KheZGWSRM4= sha256:z08KGoUV8UdlBy2A4YVzbbpbK74Q25gZkGMaTkpnl10=
User-Agent: Pan/0.149 (Bellevue; 4c157ba)
View all headers

On Sat, 28 Sep 2024 17:02:39 -0400, Chris Ahlstrom wrote:

> rbowman wrote this copyrighted missive and expects royalties:
>
>> On Sat, 28 Sep 2024 07:52:11 -0400, CrudeSausage wrote:
>>
>>> If this indeed solves the problem without compromising functionality,
>>> all the better. Considering how it was presented, it truly seemed like
>>> an issue whose solution involved crippling the operating system.
>>
>> The sky is falling! The sky is falling! The tech world loves click
>> generating headlines just as much as the MSM.
>
> 1. What outfits are part of the "MSM". Is Fox News part of the MSM,
> based on its popularity?

Certainly. I cast a wide net and it's all about advertising, or 'eyeballs'
as they say.

Not to get into the gun thing but 'Guns & Ammo' magazine offers 'specials'
that generally come down to $12 a year subscriptions. I also get the
'American Rifleman' which is part of the NRA membership. The format is a
little different so I decided $12 was too much for another mailbox filler
and didn't renew. I then got many warning and offers and still didn't
renew. The magazine keeps coming.

What is important for most magazines is their circulation numbers that
they use to peddle advertising. $12 is chump change compared to how many
magazines they mail each month.

Typically I read https://www.theregister.com/, https://arstechnica.com/,
https://betanews.com/, and https://thehackernews.com/. I haven't figured
out the first two since they don't seem to be peddling anything. The other
two a subtle or not so subtle. https://gizmodo.com/ seems fairly clean.
https://www.engadget.com/ can be interesting but it's definitely a
huckster site.

> 2. All sites want "clicks". It helps pay the bills.

The ones that puzzle me are the ones that don't force a registration and
don't have 'see the price on Amazon' buttons. Cui bono?

Subject: Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealed on October 6th
From: CrudeSausage
Newsgroups: comp.os.linux.advocacy
Organization: usenet-news.net
Date: Sun, 29 Sep 2024 10:49 UTC
References: 1 2 3 4 5 6 7 8
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!news.mixmin.net!news.neodome.net!feeder2.feed.ams11.usenet.farm!feed.usenet.farm!peer01.ams4!peer.am4.highwinds-media.com!peer01.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx10.iad.POSTED!not-for-mail
MIME-Version: 1.0
User-Agent: Betterbird (Windows)
Subject: Re: 9.9/10 security vulnerability affecting Linux (and others) set to
be revealed on October 6th
Newsgroups: comp.os.linux.advocacy
References: <2O1JO.214184$FzW1.145017@fx14.iad> <vd2mdm$1ue8$1@dont-email.me>
<alcJO.194436$kxD8.182014@fx11.iad> <vd5bkk$jdi1$1@dont-email.me>
<cJxJO.172505$1m96.122070@fx15.iad> <vd7dt1$tcgq$1@dont-email.me>
<L5SJO.109033$WtV9.49623@fx10.iad> <llr1knFm711U2@mid.individual.net>
Content-Language: en-US
From: crude@sausa.ge (CrudeSausage)
In-Reply-To: <llr1knFm711U2@mid.individual.net>
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Lines: 21
Message-ID: <QgaKO.113140$WtV9.90855@fx10.iad>
X-Complaints-To: abuse@usenet-news.net
NNTP-Posting-Date: Sun, 29 Sep 2024 10:49:20 UTC
Organization: usenet-news.net
Date: Sun, 29 Sep 2024 06:49:19 -0400
X-Received-Bytes: 2003
View all headers

On 2024-09-28 2:53 p.m., rbowman wrote:
> On Sat, 28 Sep 2024 07:52:11 -0400, CrudeSausage wrote:
>
>> If this indeed solves the problem without compromising functionality,
>> all the better. Considering how it was presented, it truly seemed like
>> an issue whose solution involved crippling the operating system.
>
> The sky is falling! The sky is falling! The tech world loves click
> generating headlines just as much as the MSM. Certainly vulnerabilities
> have been detected but most require quite a bit of conditions to be
> exploited. Meanwhile Ukrainian hackers find the real open doors.
>

Apparently, there is no short supply of them on either of the operating
systems out there. The only sure way of not getting your computer hacked
is to keep it disconnected from the Internet. An old machine running
FreeDOS and devoid of a modem should be safe enough.

--
CrudeSausage
Catholic, paleoconservative, Christ is king

Subject: Re: security vulnerability affecting Linux (and others) set to be revealed on October 6th
From: Phillip Frabott
Newsgroups: comp.os.linux.advocacy
Organization: A noiseless patient Spider
Date: Sun, 29 Sep 2024 14:54 UTC
References: 1
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nntp@fulltermprivacy.com (Phillip Frabott)
Newsgroups: comp.os.linux.advocacy
Subject: Re: security vulnerability affecting Linux (and others) set to be revealed on October 6th
Date: Sun, 29 Sep 2024 14:54:14 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 43
Message-ID: <vdbpmm$1pf2o$2@dont-email.me>
References: <QgaKO.113140$WtV9.90855@fx10.iad>
Injection-Date: Sun, 29 Sep 2024 16:54:15 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="e96421d55a93abfed6299d6ccec15d01";
logging-data="1883224"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/3hpB0wFkVD3Zoz/Q8i11p+KSnxxvSvp4="
Cancel-Lock: sha1:/Mh9ciy86n2BXZgLST64ffcksqs=
X-Newsreader: NewsLeecher v7.0 Final (http://www.newsleecher.com)
View all headers

In reply to "CrudeSausage" who wrote the following:

> On 2024-09-28 2:53 p.m., rbowman wrote:
> > On Sat, 28 Sep 2024 07:52:11 -0400, CrudeSausage wrote:
> >
> > > If this indeed solves the problem without compromising functionality,
> > > all the better. Considering how it was presented, it truly seemed like
> > > an issue whose solution involved crippling the operating system.
> >
> > The sky is falling! The sky is falling! The tech world loves click
> > generating headlines just as much as the MSM. Certainly vulnerabilities
> > have been detected but most require quite a bit of conditions to be
> > exploited. Meanwhile Ukrainian hackers find the real open doors.
> >
>
> Apparently, there is no short supply of them on either of the operating
> systems out there. The only sure way of not getting your computer hacked
> is to keep it disconnected from the Internet. An old machine running
> FreeDOS and devoid of a modem should be safe enough.
>
> --
> CrudeSausage
> Catholic, paleoconservative, Christ is king

Well, you know what they say...

"The only winning move is not to play." - Wargames 1983

Nothing is 100% safe. But Linux is, in my opinion, still much safer then Windows
and Mac.
Phillip Frabott
----------
- Adam: Is a void really a void if it returns?
- Jack: No, it's just nullspace at that point.
----------

--
----------------------------------------- --- -- -
Posted with NewsLeecher v7.0 Final
Free Newsreader @ http://www.newsleecher.com/
------------------------------- ----- ---- -- -

Subject: Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealed on October 6th
From: RonB
Newsgroups: comp.os.linux.advocacy
Organization: A noiseless patient Spider
Date: Sun, 29 Sep 2024 17:00 UTC
References: 1 2 3 4 5 6 7 8 9
Path: eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: ronb02NOSPAM@gmail.com (RonB)
Newsgroups: comp.os.linux.advocacy
Subject: Re: 9.9/10 security vulnerability affecting Linux (and others) set
to be revealed on October 6th
Date: Sun, 29 Sep 2024 17:00:41 -0000 (UTC)
Organization: A noiseless patient Spider
Lines: 37
Message-ID: <vdc13p$1qkcp$1@dont-email.me>
References: <2O1JO.214184$FzW1.145017@fx14.iad>
<vd2mdm$1ue8$1@dont-email.me> <alcJO.194436$kxD8.182014@fx11.iad>
<vd5bkk$jdi1$1@dont-email.me> <cJxJO.172505$1m96.122070@fx15.iad>
<vd7dt1$tcgq$1@dont-email.me> <L5SJO.109033$WtV9.49623@fx10.iad>
<llr1knFm711U2@mid.individual.net> <QgaKO.113140$WtV9.90855@fx10.iad>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Injection-Date: Sun, 29 Sep 2024 19:00:41 +0200 (CEST)
Injection-Info: dont-email.me; posting-host="ada1a2d3795a5818b0bdc3fcf2b63556";
logging-data="1921433"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/KFoOpJMR7twxvmh54pRZy"
User-Agent: slrn/1.0.3 (Linux)
Cancel-Lock: sha1:yg4/tb3pX1J0e2jF9eaFoyCk3Vs=
View all headers

On 2024-09-29, CrudeSausage <crude@sausa.ge> wrote:
> On 2024-09-28 2:53 p.m., rbowman wrote:
>> On Sat, 28 Sep 2024 07:52:11 -0400, CrudeSausage wrote:
>>
>>> If this indeed solves the problem without compromising functionality,
>>> all the better. Considering how it was presented, it truly seemed like
>>> an issue whose solution involved crippling the operating system.
>>
>> The sky is falling! The sky is falling! The tech world loves click
>> generating headlines just as much as the MSM. Certainly vulnerabilities
>> have been detected but most require quite a bit of conditions to be
>> exploited. Meanwhile Ukrainian hackers find the real open doors.
>>
>
> Apparently, there is no short supply of them on either of the operating
> systems out there. The only sure way of not getting your computer hacked
> is to keep it disconnected from the Internet. An old machine running
> FreeDOS and devoid of a modem should be safe enough.

Almost always, with Linux, the "sky is falling" issue is hypothetical. Lots
of ifs. If you do this, and that and this... you might get hacked... maybe.

In the Windows world, when a virus (or a problem with an application) issue
arises, people actually suffer outages. It's not hypothetical. Just recently
many Windows computers went down with BSODs because of a CrowdStrike update
because of the way Microsoft let an application update cripple Windows.
Admittedly, I've seen a lot fewer of these screw-ups in recent years, but
they still happen.

I don't know of any any Linux computers that were successfully attacked with
this CUPS issue. As far as I know it was all hypothetical... this "could"
happen with a lot of "ifs" added. And that is normally the case with Linux
security issues.

--
“Evil is not able to create anything new, it can only distort and destroy
what has been invented or made by the forces of good.” —J.R.R. Tolkien

Subject: Re: 9.9/10 security vulnerability affecting Linux (and others) set to be revealed on October 6th
From: rbowman
Newsgroups: comp.os.linux.advocacy
Date: Sun, 29 Sep 2024 19:21 UTC
References: 1 2 3 4 5 6 7 8 9
Path: eternal-september.org!news.eternal-september.org!feeder3.eternal-september.org!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: bowman@montana.com (rbowman)
Newsgroups: comp.os.linux.advocacy
Subject: Re: 9.9/10 security vulnerability affecting Linux (and others) set to
be revealed on October 6th
Date: 29 Sep 2024 19:21:42 GMT
Lines: 11
Message-ID: <lltnm5F3ksjU3@mid.individual.net>
References: <2O1JO.214184$FzW1.145017@fx14.iad> <vd2mdm$1ue8$1@dont-email.me>
<alcJO.194436$kxD8.182014@fx11.iad> <vd5bkk$jdi1$1@dont-email.me>
<cJxJO.172505$1m96.122070@fx15.iad> <vd7dt1$tcgq$1@dont-email.me>
<L5SJO.109033$WtV9.49623@fx10.iad> <llr1knFm711U2@mid.individual.net>
<QgaKO.113140$WtV9.90855@fx10.iad>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
X-Trace: individual.net SY+/Gysh5zef2AxhWVhQOQTd0AUM/bgc7jfWiS233rDPJmjLdf
Cancel-Lock: sha1:Sq39Qvi3ci41sLdZ1j1elcPLMHo= sha256:DBOMUXyTlILMKEtvMNeBR3hG2iuu69JzMYWdC2oeHwY=
User-Agent: Pan/0.149 (Bellevue; 4c157ba)
View all headers

On Sun, 29 Sep 2024 06:49:19 -0400, CrudeSausage wrote:

> Apparently, there is no short supply of them on either of the operating
> systems out there. The only sure way of not getting your computer hacked
> is to keep it disconnected from the Internet. An old machine running
> FreeDOS and devoid of a modem should be safe enough.

For a one-user personal computer an air gap works fine. Get enough people
with access to the network some damned fool will have to sneak a peek at
the thumb drive they found in the parking lot.

Pages:12

rocksolid light 0.9.8
clearnet tor