HN user

cpach

7,990 karma

Sono Rintracciabile.

Residing in Södermanland, Sweden.

Get in touch? E-mail: c (at) tunnel53 (dot) net

Website: https://www.tunnel53.net/

Interesting HN people to follow: ('tptacek 'cperciva 'tlb 'FiloSottile 'Animats 'DannyBee 'mcpherrinm 'phasmantistes 'pbsd 'patio11)

Posts132
Comments4,235
View on HN
trellis.net 10d ago

Microsoft adjusts climate agenda as emissions leap

cpach
4pts0
www.cio.com 4mo ago

IBM looks beyond short-term AI gains, tripling entry-level hiring

cpach
3pts0
adamcaudill.com 6mo ago

Lessons Learned from 20 Years and Why You Should Blog

cpach
2pts0
hsm.tunnel53.net 10mo ago

Using DNS for responding to ACME challenges

cpach
2pts0
www.theguardian.com 11mo ago

Supersized stick insect discovered in high-altitude trees in Australia

cpach
6pts6
datatracker.ietf.org 12mo ago

RFC 9773: Acme Renewal Information (ARI) Extension

cpach
2pts0
en.wikipedia.org 1y ago

Exhumation and Reburial of Richard III of England

cpach
1pts0
pivot-to-ai.com 1y ago

$119 Springer cancer treatments book: 'As an AI language model '

cpach
2pts0
julien.danjou.info 1y ago

Why French Tech Is Playing Not to Lose

cpach
4pts3
bsky.app 1y ago

Tuscolo Static Certificate Transparency Log

cpach
2pts0
www.independent.co.uk 1y ago

Man speaks to killer from beyond the grave in Arizona courtroom through AI video

cpach
3pts0
mjtsai.com 1y ago

Rotten

cpach
2pts0
www.theguardian.com 1y ago

Technology has created more jobs than it has destroyed (2015)

cpach
1pts1
www.businessinsider.com 1y ago

Microsoft's performance-based job cuts have started

cpach
4pts0
www.digitalmusicnews.com 1y ago

Spotify Shuts Down ‘Unwrapped’ Artist Royalty Calculator with Legal Threats

cpach
219pts272
www.theguardian.com 1y ago

'Entire ecosystem' of fossils 8.7M years old found under Los Angeles high school

cpach
90pts23
blog.cloudflare.com 1y ago

Avoiding downtime: modern alternatives to outdated certificate pinning practices

cpach
45pts36
github.com 1y ago

Kubernetes the Harder Way

cpach
24pts4
www.pnas.org 1y ago

The non-Riemannian nature of perceptual color space (2022)

cpach
85pts43
www.fintechfutures.com 2y ago

Klarna sells checkout business to investor consortium

cpach
2pts0
www.atlasobscura.com 2y ago

The Dinner Party That Served Up 50k-Year-Old Bison Stew (2018)

cpach
71pts17
512pixels.net 2y ago

Logitech's Mouse Software Now Includes ChatGPT Support

cpach
2pts0
www.theguardian.com 2y ago

Dog walker, dancer, and Germany's most-wanted woman

cpach
19pts1
petersanchez.com 2y ago

Easily host Go modules on your domain

cpach
1pts0
seb.jambor.dev 2y ago

Understanding ActivityPub Part 3: The State of Mastodon

cpach
3pts0
icosahedron.website 2y ago

Type Ctrl-Shift-Alt-Win-L, LinkedIn Will Open

cpach
3pts0
glitterkitten.co.uk 2y ago

Car showed pop-up while driving

cpach
250pts242
xeiaso.net 2y ago

This isn’t the way to speed up Rust compile times

cpach
128pts155
evernote.com 2y ago

Future-Proofing Evernote’s Foundations

cpach
6pts0
josefbacik.github.io 2y ago

Using lei, b4, and mutt to do kernel development (2021)

cpach
92pts9

FWIW, you might want to consider publishing your e-mail address in your HN profile or on your website. Otherwise it’s hard for people to get in touch with you.

No, I haven’t.

My concern is to try to understand the mechanisms of the exploit.

Copy Fail is not simply ”hey, kernel, give me root”. I would say it’s more general than that. It’s rather: ”Hey, kernel, when you present file /foo to a process, make the contents of that file appear according to my wishes”. Which can be used (in various ways) to advance the attacker’s position.

That’s why I think it’s interesting to ponder if that power allows the attacker to simply sneak past security policies such as allowPrivilegeEscalation=false.

If so, I would look into applying a decent seccomp profile.

Other hardening solutions could be to run the workloads inside of a VM such as Firecracker, or gVisor. But that might be more work to implement compared to seccomp.

I would say any sanely written application would fall back to doing the requested operations in userspace if it cannot use the AF_ALG socket.

It could fail though. But I have not yet heard of anyone noticing big problems due to disabling the problematic modules. And I have not noticed any such issues on our systems at ${DAYJOB}.

IMHO, since these parts of the Linux kernel are so crappy I personally would say disabling them is a good default choice. YMMV. But if you encounter problems, then you can always re-enable the modules. (Preferably after upgrading your kernel, obviously.)

Good enough for what?

I could be wrong, but I’m not sure those settings are enough to mitigate Copy Fail.

If your distro offers a patched kernel, it’s best to upgrade to that one and reboot.

You can also disable the vulnerable module (how to do it depends on what distro you’re using). But if you stay on an old unpatched kernel you might be exposed to other vulnerabilites.