{"id":39211,"date":"2019-07-01T10:34:55","date_gmt":"2019-07-01T10:34:55","guid":{"rendered":"http:\/\/icloud.pe\/blog\/?guid=b7a2fd80332f4593338c479a9e524deb"},"modified":"2019-07-01T10:34:55","modified_gmt":"2019-07-01T10:34:55","slug":"microsoft-bids-for-behind-the-scenes-access-to-linux-flaws","status":"publish","type":"post","link":"https:\/\/icloud.pe\/blog\/microsoft-bids-for-behind-the-scenes-access-to-linux-flaws\/","title":{"rendered":"Microsoft bids for behind-the-scenes access to Linux flaws"},"content":{"rendered":"<p><span class=\"field field-name-field-author field-type-node-reference field-label-hidden\"><br \/>\n      <span class=\"field-item even\"><a href=\"https:\/\/www.cloudpro.co.uk\/authors\/keumars-afifi-sabet\">Keumars Afifi-Sabet<\/a><\/span><br \/>\n  <\/span><\/p>\n<div class=\"field field-name-field-published-date field-type-datetime field-label-hidden\">\n<div class=\"field-items\">\n<div class=\"field-item even\"><span class=\"date-display-single\">1 Jul, 2019<\/span><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"short-teaser\">\n<a href=\"https:\/\/www.cloudpro.co.uk\/\" title=\"\" class=\"combined-link\"><\/a><\/p>\n<div class=\"field field-name-body\">\n<p> Microsoft has applied to join two security boards for representatives of Linux distributions to discuss and coordinate vulnerabilities and security issues.<\/p>\n<p>The linux-distros mailing list is used as a private channel where developers can discuss flaws in Linux systems and co-ordinate fixes for issues that have not yet reached the public domain. The oss-security group is used to discuss vulnerabilities that are already known.<\/p>\n<p>Microsoft&#8217;s &#8216;Linux Kernal Hacker&#8217; Sasha Levin <a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/06\/26\/2\" >sent an application to join the security boards last week<\/a>, which could see the Windows developer to be party to behind-closed-doors conversations on ongoing security issues.<\/p>\n<p>Members of this community include Chrome OS, Red Hat, Oracle, SUSEand Amazon Linux AMI.<\/p>\n<p>There are several criteria that organisations need to meet to join the linux-distros group. For example, Levin cited Azure Sphere and Windows Subsystem for Linux v2 as examples of the company actively maintaining Unix-like operating system distro with open source components.<\/p>\n<p>Successful applications must also have a userbase that isn&#8217;t limited to their own organisation, which Microsoft said it fits through millions of cores its customers run on systems such as those aforementioned.<\/p>\n<p>Organisations must also be able to demonstrate at least a year-long track record of fixing vulnerabilities, including some on Linux distros, and releasing fixes for known issues within 10 days or fewer.<\/p>\n<p>Applications would also have to gain the recommendation of an individual who has been active on oss-security of years but is not affiliated with the organisation. Levin copied in renowned Linux developer Greg Kroah-Hartman, who replied separately in the email chain to vouch for Microsoft&#8217;s submission.<\/p>\n<p>&#8220;I can vouch for Sasha,&#8221; Kroah-Hartman said. &#8220;He is a long-time kernel developer and has been helping with the stable kernel releases for a few years now, with full write permissions to the stable kernel trees.<\/p>\n<p>&#8220;I also suggested that Microsoft join linux-distros a year or so ago when it became evident that they were becoming a Linux distro, and it is good to see that they are now doing so.&#8221;<\/p>\n<p>Microsoft has shifted towards embracing Linux technology and open source principles over the last few years, and increasingly under CEO Satya Nadella&#8217;s leadership. This is after its former CEO Steve Ballmer infamously referred to Linux as a &#8220;malignant cancer&#8221; and &#8220;communism&#8221; almost 20 years ago.<\/p>\n<p>A significant change happened a decade ago when <a href=\"https:\/\/www.itpro.co.uk\/612976\/microsoft-surprises-with-linux-code-submission\" >Microsoft released 20,000 lines of code to the Linux open source community<\/a>. This led the executive director of the Linux Foundation Jim Zemlin to declare at the time that &#8220;hell has frozen over&#8221;.<\/p>\n<p>To demonstrate how much Linux popularity has surged in recent years, Sasha Levin added in a <a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/06\/27\/7\" >further message to the email chain<\/a> that the usage of this technology on Microsoft&#8217;s Azure cloud services has now surpassed Windows. This is just two years after <a href=\"https:\/\/twitter.com\/msdevuk\/status\/925364206500765696?lang=en\" >Microsoft said that 40% of virtual machines in Azure are running Linux<\/a>.<\/p>\n<p>As a result of this increased usage, Microsoft&#8217;s security centre has started receiving a higher volume of security reports of issues with Linux code from users and from vendors. <\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>      Keumars Afifi-Sabet<\/p>\n<p>        1 Jul, 2019    <\/p>\n<p>       Microsoft has applied to join two security boards for representatives of Linux distributions to discuss and coordinate vulnerabilities and security issues.<br \/>\nThe linux-distros mailing list &#8230;<\/p>\n","protected":false},"author":433,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-39211","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/users\/433"}],"replies":[{"embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/comments?post=39211"}],"version-history":[{"count":3,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39211\/revisions"}],"predecessor-version":[{"id":39225,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/posts\/39211\/revisions\/39225"}],"wp:attachment":[{"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/media?parent=39211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/categories?post=39211"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/icloud.pe\/blog\/wp-json\/wp\/v2\/tags?post=39211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}