HNNewShowAskJobs
Built with Tanstack Start
The Journey of Bypassing Ubuntu's Unprivileged Namespace Restriction(u1f383.github.io)
26 points by Bogdanp 3 days ago | 4 comments
  • 0xbadcafebee3 days ago

    > As a researcher, it was frustrating to see various bypass methods being publicly disclosed while I couldn’t share my own work because I had already reported it to ZDI. After a few days with no updates, I even emailed ZDI to ask if I could withdraw my submission. Fortunately, my boss, Orange Tsai, stepped in just in time and patiently walked me through the pros and cons of doing so. That helped me regain my composure, and I ended up sending another email to retract my withdrawal request.

    If you feel emotion when writing an email (or Slack message), put it in draft and look at it tomorrow. I've never not edited or scrapped it the next day.

    • rexer3 days ago |parent

      > I've never not edited or scrapped it the next day.

      There's definitely a balance. Showing a little emotion can be a good thing, necessary even

    • bravetraveler3 days ago |parent

      Fascinating. If I delay my response, usually, there will be more things that demand an even larger response.

  • throw2903481903 days ago

    > As a researcher, it was frustrating to see various bypass methods being publicly disclosed while I couldn’t share my own work because I had already reported it to ZDI. After a few days with no updates, I even emailed ZDI to ask if I could withdraw my submission

    security@$COMPANY.DOMAIN inboxes are constantly inundated with BS security reports phishing for a payout. The situation has only gotten worse with LLMs.

    Expecting a quick response is ridiculous. You should try taking on a role where it's your job to sift through all those emails .