Comment by turkeyboi

3 days ago

Why does this need to be a whole ass website

You're not going to get anywhere in the security sector unless you gain notoriety i.e. are noticed.

This appears to come from dressing up like Elton John in a feather suit and hiring a marketing team.

Why not? This weird complaint has been happening since ~2010 and it has never made any sense. You are strictly better off with the website than without it. When it was vulnerability researchers getting all peevish about the status competition they were running, I at least understood where the complaint was coming from, but even among practitioners, branded vulnerabilities are so much the norm at this point that there's no status implication anymore.

  • > You are strictly better off with the website than without it.

    Why? This is a better resource in every way: https://cgit.freebsd.org/src/commit/?id=000d5b52c19ff3858a6f...

    It details the actual problem instead of showing off tired stack exploit tricks.

    • No, that commit log is obviously not better than the page explaining the vulnerability and the exploit vectors.

      Case in point: what's "tired" about the stack exploitation techniques they're using here?

      And, while you're not right, even stipulating that you were, what would that matter? How is anyone better off with less explanation of a vulnerability?

      2 replies →

    • Is that even the fix though? The problem sizeof*groups expression has already been removed by that point. This fixes something but it's not obviously related to the vulnerability description.

      git log -S suggests 4cd93df95e697942adf0ff038fc8f357cbb07cf9, which looks more likely: https://cgit.freebsd.org/src/commit/?id=4cd93df95e697942adf0... - though not to say you don't want the later commit too. I'm sure you do.

It gives legitimacy to whatever whimsical name was given to a vulnerability by registering the domain.

CVE numbers are for boring professionals.

Have you not done anything remotely interesting for you that you want to build a website so the whole world can see it?

What?

Is there something in this website that feels unnecessary? It seems like a good format of sharing high quality information.

This looks like a full bug into a complete root escalation of a kernel. That's hard to do and deserving of praise. The fact that we have a writeup organized like this is awesome.

-------

This is sort of the expert level stuff that I thought HackerNews would most enjoy.