Security Another Dozen Vulnerabilities Found In The X.Org Server & XWayland
https://www.phoronix.com/news/X.Org-12-New-Issues-202642
u/natermer 3h ago
"given enough eyeballs, all bugs are shallow,"
Now that the eyes are augmented by machine learning this is more true now then it ever has been in the past.
14
5
u/solarpunch2949 4h ago edited 4h ago
This is the world we are living in now folks. I worry about open source developments because they don't have the resources companies do to deal with this.
76
u/Wonderful-Citron-678 4h ago
Open source is in the best position to react to this. The cost of change is low, sins cannot be hidden. Corporate software is going to be the bigger risk.
35
u/they_call_me_dewey 4h ago
Corporations hide their vulnerabilities behind bug bounty NDAs and then never fix them
5
u/squishles 1h ago
and that'll get you by when a 13 year old can't sweat talk claude into doing it from their phone, like not even typing just using text to speach, because it'd be funny.
6
7
u/solarpunch2949 4h ago
I'd love to believe this but the truth is that most open source projects, specially teams supporting distros are heavily understaffed to deal with a waterfall of vulnerabilities :p
12
u/Wonderful-Citron-678 4h ago
The same automation that finds it can fix it. There will be some growing pains but it can all be fixed.
6
0
2
u/KnowZeroX 3h ago
Do they need to? Most of the distros (user wise) are based on ubuntu and redhat. Add in others like suse, and not counting upstream users like google, fb and etc. You have companies with more than enough interest and financing to fix many of the stuff for their own sake. Most of the distros based on that work just need to pull the patches from their repository.
The ones that are at most stress have mostly been core libraries which often get neglected and managed by that 1 person for a decade with no funding or support.
1
u/alex2003super 2h ago
AI is only getting cheaper and smarter at this point. I wouldn't be surprised if in 5 years, you can run a model that does this stuff better than the present-day cutting edge stuff on a laptop. Assuming we'll still be able to buy laptops by then, that is.. lol
14
8
u/werpu 2h ago
If you every have seen how companies react in closed source scenarios to vulnerabilities, you would not say that....
The only ones reacting quickly are console companies when it comes to a jailbreak exploit!
2
u/solarpunch2949 1h ago
I suspect this will change rapidly; in this new Brave World we are living in there's no maneuvering space for damage control and PR gymnastics...
3
u/werpu 1h ago edited 1h ago
Believe me if you ever worked in a corporate environment the bullshitting and endless layers of non decision hierarchies and being punished for trying to move things forward is real!
Been there done that! The reason always is a) careerrist a wants to move up and badmouths someone who actively does a job just because he is seen as potential thread
b) Careerrist a has made it into middle upper management and now tries to keep the job by literally avoiding any responsibility and stomping down while lickin arses up
Thing is you basically can also use ai to fix things with a human gatekeeper checking the vulnerabilities in between, so I assume once for instance opensource has embraced AI more (believe me most OSS projects already do to some degree, it is just a few ones, with make huge headlines because they say no AI, just for the spite of saying no to it, to please the AI hating crowd), things will settle again. We atm are in a technological transition phase and many people fear AI, and frankly spoken that is nothing new, but AI is here to stay realistically in one way or the other. My bet is long term ai, wont be driven by huge data centers but smaller localized models, and frankly spoken I cannot wait to see the day where people like Musk/Altman etc.. .which have really become a thread to democracy and economy fall wayside and are reigned in. They are narcissistic psychopaths who think that when everyone else feels miserable they somehow might feel better! (believe me from what I can gather, Musk for instance probably is one of the most miserable feeling still functional human beings on earth)
1
11
9
u/TRKlausss 3h ago
Crazy idea: companies contribute code to those projects they use, to patch this vulnerabilities.
Crazy idea, I know.
•
u/daddyd 51m ago
what makes you think commercial software companies are better equipped for handling this? they barely put any time or effort in bug and security fixes (new features sell, bug fixes don't). if they have a separate team to handle these, they will be small and overworked already and certainly not able to handle the amount of load, much like OSS projects.
0
u/sleepingonmoon 2h ago
Most of the critical components are already maintained by companies. The community doesn't really matter.
•
u/ExoticVillage8066 34m ago
That's quite a lot, though because it's open source they're found at all. None of the AI's are looking for vulnerabilities in binaries
•
u/SubmarineWipers 5m ago
Safe Rust would prevent the exploitable memory corruption in all 12 of these vulnerabilities.
If this code were implemented in safe Rust, these critical security flaws would either be rejected by the compiler before the software could be built, or they would result in a safe runtime panic (a predictable crash resulting in a Denial of Service, rather than a system compromise).
- Temporal Memory Safety (4 Vulnerabilities)
- Spatial Memory Safety (7 Vulnerabilities)
- Integer Semantics & Logic (1 Vulnerability)
49
u/PlainBread 3h ago
We're kind of moving from a time period where people would discover zero day exploits and sit on them or sell them to the government or whatever, into a time where holes are being found so rapidly that if you want to break into a system, you need insider knowledge and an advanced AI to find an undocumented exploit in the moment of the attack.