Greg Kroah-Hartman talks about security in the Linux kernel

logo.

Cybersecurity is a field that has gained much prominence in corporate environments in recent times.

While it is true that this problem has always been important for companies, new areas, such as cloud computing, Ransomware and the Meltdown and Spectre vulnerabilities, have raised concerns at levels never seen before.

In a recent interview with Linux.com, Greg Kroah-Hartman, a Linux kernel developer, discussed security in the Linux kernel and how they address security issues that have arisen.

Security First in Linux

Greg Kroah-Hartman, one of the heavy hitters in Linux kernel development, gave a statement to the Linux.com site on how to deal with and fix security issues.

He spoke about how they handle and fix security problems , and from what he himself acknowledged, it seems that sometimes their origin comes from the most unexpected places.

For example, Kroah-Hartman fixed a faulty bug some time ago, but three years later Red Hat discovered that it was actually a vulnerability.

This was married to a statement made by Linus Torvalds, in which he said that most security flaws were bugs.

In a Q&A video interview with the Linux Foundation, Greg Kroah-Hartman talks about the issues with Meltdown and Specter and why the Linux Kernel, despite having found a variety of bugs found in it, from his perspective , it is safer.

Swapnil Bhartiya gave the Linux Foundation a short video interview with Greg Kroah-Hartman, who is virtually running the "core business" during Linus' absence.

The kernel developer confirmed that Linux security is a very important issue and has a high priority within its development.

This is partly because "Linux drives the world." For example, more and more people are storing sensitive data on their smartphones and do not want third parties to access it.

When asked which kernel layer bothered him the most, Kroah-Hartman called out the Meltdown and Specter bugs.

Too much responsibility for developers

Gregkroah Hartman

What bothers developers is that they have to fix something that they don't see as being in their area of ​​responsibility, namely, the hardware.

Usually you work in the kernel around the "black box CPU" around. But CPUs would use more and more tricks to improve performance. These tricks would occasionally fall on the feet of developers, and the kernel would have to fix these problems.

Overall, Kroah-Hartman was convinced that the kernel is more secure. Among other things, the testing infrastructure that has been developed over the years will help prevent bugs from appearing when a kernel patch is released to the public.

The fact that fuzzers like Google's Syzcaller find a number of bugs in the Kernel can be explained by the fact that security researchers today are testing deeper levels of the Kernel to detect bugs that have never been tested for before.

At these levels there are errors that sometimes already exist for a long time. So far, only a few people have looked at this code.

So Kroah-Hartman wouldn't say the "world is on fire", but thanks to sophisticated testing, developers are now very good at finding kernel bugs.

The programmer emphasized that they are "doing more testing" to ensure maximum security for the Linux Kernel, and that in the last round of security fixes they worked for four months alone because they were embargoed.

But after a complicated process, he acknowledges that "things are certainly looking up."

The good news for professionals is that this increased concern opens up new job opportunities, as cybersecurity specialists will be increasingly sought after.


Add as preferred source in Google