back to article Linux infosec outfit does a Torvalds, rageblocks innocent vuln spotter

An open source security firm has blocked a security researcher who reported flaws in a recently issued patch in an apparent fit of pique. Hector Martin took to Twitter on Tuesday to note a trivial crashing vulnerability in a recently issued patch by Grsecurity. “I literally crashed my box by pasting a bunch of text into a …

  1. Halfmad
    Trollface

    Oh no!

    Blocked on twitter AND by IP, no IT security person will ever manage to circumvent such draconian measures!

    1. wolfetone Silver badge

      Re: Oh no!

      But he's alright to contact them through Facebook, yeah?

  2. m0rt

    The best thing I took from reddit thread:

    [–]nananana__batman 33 points 5 hours ago

    In soviet kernel, devs bug you.

    *sniggers*

  3. Dan 55 Silver badge

    MOAR AGILE

    If you look at the patch (in Marcan's Twitter feed), it's a pretty stupid one.

  4. EJ

    A ringing endorsement of the firm's professionalism. About the same for the researcher.

    1. FuzzyWuzzys
      Thumb Up

      Sod 'em then!

      Exactly what I was thinking, put them on the growing list of twats who obviously don't value their users/customers.

  5. Anonymous Coward
    Anonymous Coward

    Not sure how this has anything do with Linus other than a poor attempt at clickbait.

    1. Anonymous Coward
      Anonymous Coward

      re: how this has anything do with Linus

      It's because he's famous for this kind of dickish behaviour.

      1. Anonymous Coward
        Anonymous Coward

        Re: re: how this has anything do with Linus

        >It's because he's famous for this kind of dickish behaviour.

        Has Linus blocked anyone from the LKML for pointing out an issue? I don't think he even has the power to do that. The closest thing Linus has done is say he won't accept patches from people that keep sending him crap until they get their act together and that's a real stretch.

        p.s. don't believe everything you read on the register about Linus. They have been known to stretch the truth too far and outright have no idea what they are talking about.

      2. Anonymous Coward
        Anonymous Coward

        Re: re: how this has anything do with Linus

        > It's because he's famous for this kind of dickish behaviour.

        Only if you read idiotic red-top blogs such as this one¹. In reality, he's a pretty personable bloke with the people skills you would expect from a project manager for the biggest software project in history.

        ¹ Sadly, every other vaguely IT news source seems to be American, which presents a bit of a cultural challenge for me. But if anyone can recommend any other right-pondian IT publications, I'd be indebted. Not too right-pondian though! I can decipher Russian with some difficulty but anything East of that poses a problem.

        1. Anonymous Coward
          Anonymous Coward

          Re: Only if you read idiotic red-top blogs such as this one

          No, most people who know of him know him as the shouty rude computer man. Kind of like an open source Steve Ballmer....

        2. Anonymous Coward
          Anonymous Coward

          Re: re: how this has anything do with Linus

          There is another rag which was set up by one of El Reg's founders; not sure whether it can be mentioned here with impunity.

          1. Nano nano

            Re: re: how this has anything do with Linus

            I'd make Inquiries about that.

  6. Destroy All Monsters Silver badge
    Gimp

    "Not for you?"

    That's against the GPL.

    (The GPL Defamation League will be in touch!)

  7. Doctor Syntax Silver badge

    Shooting the messanger

    Never a good idea.

    1. Anonymous Coward
      Anonymous Coward

      Re: Shooting the messanger

      > Never a good idea.

      And the messenger?

  8. Anonymous Coward
    Mushroom

    maybe this explains why ...

    ... grsecurity's patches aren't merged in the Linux Kernel tree.

    This grsecurity guy may very well be a brilliant researcher and programmer and everything, but diplomacy or making friends is definitely not his strong suit.

    See this thread at Reddit.

  9. Jon Gibbins
    FAIL

    ... and THAT'S a company I'd LOVE to do business with!

  10. Anonymous Coward
    WTF?

    grsecurity

    So, grsecurity make money (I presume) by pointing out holes in others security, but grsecurity don't like it when fellow security people point out flaws in grsecurity's security software.

    So grsecurity react to a hole in grsecuritys software by banning anyone that mentions the issue in grsecurity's software?

    Way to go grsecurity.

    I may just pop over to twitter, mention the grsecurity issue and tag in @grsecurity, to get grsecuirty to ban me, although after this, something tells me I wouldn't trust grsecurity with my security.

    Streisand effect anyone?

    1. Ramazan

      Re: grsecurity

      > So grsecurity react to a hole in grsecuritys software

      > by banning anyone that mentions the issue in grsecurity's software?

      I sent a patch to spender once and he just accepted it, without any Monty Python Shitfan Circus stuff.

    2. Anonymous Coward
      Anonymous Coward

      Re: grsecurity

      > So, grsecurity make money (I presume) by pointing out holes in others security

      You presume wrong I'm afraid. GRSecurity write kernel-hardening patches which plug/mitigate security holes in other software. They pretty much invented many security features which are now standard in many operating systems, such as ASLR and DEP.

      Rightly or wrongly, they took offence at someone's high-horse report of a minor albeit stupid bug in one of their recent patches.

      1. Anonymous Coward
        Anonymous Coward

        @AC - Re: grsecurity

        I'd vote for wrongly!

  11. Daniel B.

    Oh this is interesting...

    @grsecurity is now "protected". Which means they're throwing an even worse tantrum than the one reported here. Check it out!

  12. Aodhhan

    Let's all get banned by GRSecurity

    GRSecurity, if you thought nobody checked your work before, you better believe they will now. Better increase your QA/QC budget.

    For now it will become a badge of honor to get GRSecurity to publicly berate you like a 9 year old.

  13. Aodhhan

    Linus' problem...

    Maybe he is a good guy. I think Obama is probably a good guy... but they both suffer from, "I'm always right, you're always wrong (even though you're the expert), syndrome".

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like