{"id":382,"date":"2010-09-14T11:22:16","date_gmt":"2010-09-14T19:22:16","guid":{"rendered":"http:\/\/www.outflux.net\/blog\/?p=382"},"modified":"2010-09-14T11:22:16","modified_gmt":"2010-09-14T19:22:16","slug":"my-part-in-the-ecosystem","status":"publish","type":"post","link":"https:\/\/outflux.net\/blog\/archives\/2010\/09\/14\/my-part-in-the-ecosystem\/","title":{"rendered":"my part in the ecosystem"},"content":{"rendered":"<p>I was asked to write about what I do at <a href=\"http:\/\/www.canonical.com\/\">Canonical<\/a> and what I do in the <a href=\"http:\/\/en.wikipedia.org\/wiki\/Free_software\">Free Software<\/a> community at large. There is obviously a great deal of overlap, but I&#8217;ll start with the things I&#8217;m involved with when I&#8217;m wearing my &#8220;<a href=\"http:\/\/www.ubuntu.com\/\">Ubuntu<\/a>&#8221; hat.<\/p>\n<p>My primary job at Canonical is keeping Ubuntu secure. This means that I, along with the rest of the <a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\">Ubuntu Security Team<\/a>, coordinate with other Free Software distributions and upstream projects to publish fixes together so that everyone in the community has the smallest possible window of vulnerability, no matter if they&#8217;re running Ubuntu, <a href=\"http:\/\/www.debian.org\/\">Debian<\/a>, <a href=\"http:\/\/www.redhat.com\/\">RedHat<\/a>\/<a href=\"http:\/\/fedoraproject.org\/\">Fedora<\/a>, <a href=\"http:\/\/www.novell.com\/linux\/\">SUSE<\/a>\/<a href=\"http:\/\/en.opensuse.org\/\">openSUSE<\/a>, <a href=\"http:\/\/www.gentoo.org\/\">Gentoo<\/a>, etc. Between <a href=\"http:\/\/oss-security.openwall.org\/wiki\/mailing-lists\/vendor-sec\">vendor-sec<\/a>, <a href=\"http:\/\/oss-security.openwall.org\/wiki\/\">oss-security<\/a>, and the steady stream of new <a href=\"http:\/\/cve.mitre.org\/\">CVEs<\/a>, there is plenty going on.<\/p>\n<p>In addition to updates, the Security Team works on <a href=\"https:\/\/wiki.ubuntu.com\/Security\/Features\">pro-active security protections<\/a>. I work on userspace security hardening via patches to <a href=\"https:\/\/wiki.ubuntu.com\/CompilerFlags\">gcc<\/a> and the <a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\/Roadmap\/KernelHardening\">kernel<\/a>, and via <a href=\"http:\/\/wiki.debian.org\/Hardening\">build-wrapper<\/a> script packages. Much of this work has been related trying to <a href=\"http:\/\/www.mail-archive.com\/debian-devel@lists.debian.org\/msg277751.html\">coordinate these changes with Debian<\/a>, and to clean up unfinished pieces that were left unsolved by RedHat, who had originally developed many of the hardening features. Things like <a href=\"http:\/\/git.kernel.org\/?p=linux\/kernel\/git\/torvalds\/linux-2.6.git;a=commitdiff;h=5096add84b9e96e2e0a9c72675c442fe5433388a\">proper \/proc\/$pid\/maps permissions<\/a>, real <a href=\"http:\/\/git.kernel.org\/?p=linux\/kernel\/git\/torvalds\/linux-2.6.git;a=commitdiff;h=f06295b44c296c8fb08823a3118468ae343b60f2\">AT_RANDOM implementation<\/a>, upstreaming <a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\/Roadmap\/ExecutableStacks\">executable stack<\/a> fixing patches, upstreaming kernel <a href=\"http:\/\/git.kernel.org\/?p=linux\/kernel\/git\/frob\/linux-2.6-roland.git;a=shortlog;h=refs\/heads\/fedora\/x86-nx-emulation\">NX-emu<\/a>, etc. Most of the kernel work I&#8217;ve done has gotten upstream, but lately some of the more <a href=\"http:\/\/lwn.net\/Articles\/398607\/\">aggressive protections<\/a> have been hitting frustrating upstream roadblocks.<\/p>\n<p>Besides the hardening work, I also improve and support the <a href=\"https:\/\/apparmor.wiki.kernel.org\/index.php\/Main_Page\">AppArmor<\/a> Mandatory Access Control system, as well as write and improve <a href=\"https:\/\/wiki.ubuntu.com\/SecurityTeam\/KnowledgeBase\/AppArmorProfiles\">confinement profiles<\/a> for processes on Ubuntu. This work ends up improving everyone&#8217;s experience with AppArmor, especially now that it has gotten <a href=\"http:\/\/lwn.net\/Articles\/398191\/\">accepted upstream<\/a> in the Linux kernel.<\/p>\n<p>I audit code from time to time, both &#8220;on the clock&#8221; with Canonical and in my free time. I&#8217;m no <a href=\"http:\/\/taviso.decsystem.org\/research.html#toc1\">Tavis Ormandy<\/a>, but I try. ;) I&#8217;ve found various security issues in <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2006-5397\">Xorg<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2006-6120\">Koffice<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-0472\">s<\/a><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-0473\">m<\/a><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-0474\">b<\/a><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-0475\">4<\/a>k, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-0455\">libgd2<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-1463\">Ink<\/a><a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-1464\">scape<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-3564\">curl+GnuTLS<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-5208\">hplip<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2007-6025\">wpa_supplicant<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2008-1792\">Flickr Drupal module<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2008-1693\">poppler\/xpdf<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2008-2570\">LimeSurvey<\/a>, <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2009-1253\">tunapie<\/a>, and the <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2009-2691\">Linux<\/a> <a href=\"http:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2010-2803\">kernel<\/a>.<\/p>\n<p>With my Canonical hat off, I do all kinds of random things around the Free Software ecosystem. I&#8217;m a sysadmin for <a href=\"http:\/\/kernel.org\/\">kernel.org<\/a>. In Debian, I <a href=\"http:\/\/qa.debian.org\/developer.php?login=kees@debian.org\">maintain<\/a> a few packages, continue to try to <a href=\"http:\/\/lists.debian.org\/debian-gcc\/2009\/10\/msg00186.html\">push for security hardening<\/a>, and contribute to the <a href=\"http:\/\/security-tracker.debian.org\/tracker\/\">CVE triage<\/a> efforts of the Debian Security Team.<\/p>\n<p>I&#8217;ve written or maintain several weird projects, including <a href=\"http:\/\/outflux.net\/software\/pkgs\/mythtvfs-fuse\/\">MythTVFS<\/a> for browsing MythTV recordings, <a href=\"http:\/\/gopchop.org\/\">GOPchop<\/a> for doing non-encoding editing of MPEG2-PS streams, Perl&#8217;s <a href=\"http:\/\/search.cpan.org\/dist\/Device-SerialPort\/\">Device::SerialPort<\/a> module, and the TAP paging server <a href=\"http:\/\/sendpage.org\/\">Sendpage<\/a>.<\/p>\n<p>For a selection of things I&#8217;ve contributed to other project, I&#8217;ve implemented <a href=\"http:\/\/bugs.debian.org\/cgi-bin\/bugreport.cgi?bug=542599\">TPM RNG<\/a> access in rng-tools, made contributions to <a href=\"http:\/\/inkscape.org\/\">Inkscape<\/a>&#8216;s build and print systems, implemented <a href=\"http:\/\/www.outflux.net\/blog\/archives\/2010\/08\/12\/cryptprotect-broken\/\">CryptProtect<\/a> for <a href=\"http:\/\/www.winehq.org\/\">Wine<\/a>, wrote a PayPal <a href=\"http:\/\/outflux.net\/software\/pkgs\/ipn-agent\/\">IPN agent<\/a> in PHP that actually checks SSL certificates unlike every other implementation I could find, added additional protocol-specific <a href=\"http:\/\/cvs.openssl.org\/chngview?cn=15899\">STARTTLS negotiations<\/a> to OpenSSL, implemented the initial <a href=\"http:\/\/www.itdp.de\/mplayer-dev-eng\/2002-04\/msg00006.html\">DVD navigation support<\/a> in MPlayer, updated serial port logic in <a href=\"http:\/\/www.scantool.net\/\">Scantool<\/a> for communicating with vehicle CAN interfaces, tried to add support for new types of timeouts in <a href=\"http:\/\/www.snort.org\/\">Snort<\/a> and <a href=\"http:\/\/ettercap.sourceforge.net\/\">Ettercap<\/a>, fixed bugs in <a href=\"http:\/\/www.mutt.org\/\">mutt<\/a>, and added HPUX audio support to the Apple ][ emulator <a href=\"http:\/\/www.jurai.org\/funaho\/emulators\/XGS\/\">XGS<\/a>.<\/p>\n<p>As you can see, I like making weird\/ancient protocols, unfriendly file formats, and security features more accessible to people using Free Software. I&#8217;ve done this through patches, convincing people to take those patches, auditing code, testing fixes and features, and doing packaging work.<\/p>\n<p>When I go to conferences, I attend <a href=\"http:\/\/summit.ubuntu.com\/\">UDS<\/a>, <a href=\"http:\/\/defcon.org\/\">DefCon<\/a>, <a href=\"http:\/\/www.oscon.com\/\">OSCon<\/a>, and <a href=\"http:\/\/events.linuxfoundation.org\/events\/linuxcon\">LinuxCon<\/a>. I&#8217;ve presented in the past at OSCon on various topics including <a href=\"http:\/\/conferences.oreillynet.com\/cs\/os2005\/view\/e_sess\/6580\">security<\/a>, <a href=\"http:\/\/conferences.oreillynet.com\/cs\/os2005\/view\/e_sess\/6586\">testing<\/a>, and <a href=\"http:\/\/conferences.oreillynet.com\/cs\/os2006\/view\/e_spkr\/2205\">video formats<\/a>, and presented at the <a href=\"https:\/\/security.wiki.kernel.org\/index.php\/LinuxSecuritySummit2010\/Schedule\">Linux Security Summit<\/a> (miniconf before LinuxCon this year) on the need to upstream various out-of-tree security features available to the Linux kernel.<\/p>\n<p>I love our ecosystem, and I love being part of it. :)<\/p>\n<p style='text-align:left'>&copy; 2010, <a href=\"https:\/\/outflux.net\/blog\/\">Kees Cook<\/a>. This work is licensed under a <a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\">Creative Commons Attribution-ShareAlike 4.0 License<\/a>.<br \/><a rel=\"license\" href=\"http:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/\"><img decoding=\"async\" alt=\"CC BY-SA 4.0\" style=\"border-width:0\" src=\"https:\/\/i.creativecommons.org\/l\/by-sa\/4.0\/88x31.png\" \/><\/a> <\/p>\n","protected":false},"excerpt":{"rendered":"<p>I was asked to write about what I do at Canonical and what I do in the Free Software community at large. There is obviously a great deal of overlap, but I&#8217;ll start with the things I&#8217;m involved with when I&#8217;m wearing my &#8220;Ubuntu&#8221; hat. My primary job at Canonical is keeping Ubuntu secure. This [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5,18,2,11,4,6,14,19,12],"tags":[],"_links":{"self":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/382"}],"collection":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/comments?post=382"}],"version-history":[{"count":16,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/382\/revisions"}],"predecessor-version":[{"id":398,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/posts\/382\/revisions\/398"}],"wp:attachment":[{"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/media?parent=382"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/categories?post=382"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/outflux.net\/blog\/wp-json\/wp\/v2\/tags?post=382"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}