Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> they don't believe that vulnerabilities conceptually make sense

That's exactly what I wrote: "they have a strong belief that all kernel bugs are vulnerabilities and all vulnerabilities are just bugs; sometimes taken to the extreme in both ways".

But there is also a question of bandwidth. If a maintainer asks to bring a specific vulnerability to distros-list, the kernel security people will be reasonable. I did it last March.



How does that square with this comment from greg from today?

https://www.openwall.com/lists/oss-security/2026/05/01/3

(About heads up to distros)

> Nope, sorry, we are NOT allowed to notify anyone about anything "ahead of time" otherwise we will have to tell everyone about everything. That's the only policy by which all the legal/governmental agencies have agreed to allow us to operate in, so we are stuck with it.


I don't know, this is the one that I mentioned:

https://www.openwall.com/lists/oss-security/2026/03/30/5

You can see my name under "Timeline", I asked kindly for both distros-list and a longer embargo than usual and got them.

I guess Greg is not allowed to notify distros-list, but someone else is?


He's full of shit lol




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: