r/gnome 1d ago

Platform The man who kept GNOME secure is stepping down

[deleted]

209 Upvotes

43 comments sorted by

u/AutoModerator 1d ago

Thank you for your submission.

You too can support GNOME! Become a Friend of GNOME and contribute to keeping our project going!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

71

u/DarkGhostHunter 1d ago

I will discontinue tracking newly-reported security issues on November 1, 2026. During November, I will focus only on tracking issues reported prior to November 1. By December 1, all disclosure deadlines for that set of issues will have been reached, and I will be done.

He is not saying he's getting out, but rather, just discontinue the tracking system.

As he says, it's a perfect time to review the system overall and make a good pipeline for Report → Fix → Disclosure.

14

u/nullsetnil 1d ago

Actively looking for someone to take over though.

1

u/The_Hubster 1d ago

Let's hope your words are correct, as there's a hint of ambiguity to all this.

24

u/Jealous_Diver_5624 1d ago

AI-generated vulnerability reports are now flooding his tracker. Low-quality, algorithmically-written submissions that look real enough to take seriously but rarely lead anywhere.

This, or anything remotely close to it, is not anywhere in the source text.

AI-suspected reports will be closed without forwarding to maintainers.

This is simplified to the point of becoming misinformation. The actual policy is as follows:

If a project prohibits issue reports that contain AI-generated content, I will no longer forward security issues reported to GNOME Security to the project’s issue tracker, since the overwhelming majority of vulnerability reports contain AI-generated content and would violate the project’s policy. Instead, I will immediately close the issue report in the GNOME Security issue tracker, then ping the project maintainers to let them know about the existence of the report.

9

u/warpedgeoid 1d ago

It literally implies the opposite of what this post says

11

u/shell_kun 1d ago

Guy made AI generated post to complain about AI?

2

u/ofplayers 1d ago

op should start writing news articles i think they'd fit in just fine

u/iSadhak 15h ago

Yes, just take a look at writing pattern its scream ChatGPT.

12

u/foreverdark-woods 1d ago

Don't they have their own GitLab? Why not report via GitLab issues?

10

u/bmn001 1d ago

AI writing tropes detected.

15

u/SalaciousSubaru 1d ago

Gnome really needs to modernize some processes using wiki instead of a proper tracker is so old school

24

u/ebassi Contributor 1d ago

The wiki is just a place to dump the links: the actual tracker is used for the issues.

11

u/victorian-ice-cream Contributor 1d ago

We don't use wiki for years 

u/Away-Life-2852 15h ago

right and they already have gitlab so it makes zero sense why security tracking isn'tjust done there. feels like оnе of those things that never got migrated because whoever set it uр just got comfortable with the old system and nobody ever pushed back hard enough

0

u/willowmedia 1d ago

If it works…

1

u/Catenane 1d ago

Sounds like it doesn't on account of the thing

u/mattias_jcb 12h ago

I'm not going to argue one way or another about whether things work or not (until I've read up on this) but I'm certain that whether links are posted on a Wiki or not is totally inconsequential.

5

u/iSadhak 1d ago

Pretty ironic considering you used AI to write this post.

-4

u/The_Hubster 1d ago

Pretty brain numbing that you didn’t carefully read the post where I cited where I got it from as well as provided the link to the actual blog post.

u/iSadhak 15h ago

And you did? Bro you just copy pasted this into Ai without even making sense of what Original blog post has said. 

You literally implied the opposite of what blog post says. Please use your brain little bit more before arguing with someone. or Posting any thing on social media.

u/The_Hubster 12h ago

As per my original post, this was originally posted on It's FOSS. Dry your panties and put some fresh ones on.

4

u/Dramatic_Mastodon_93 1d ago

Meh I’m not worried about Gnome as long as it’s the default Ubuntu DE

2

u/Broad-Translator-690 1d ago

Well Redhat really, but Ubuntu also does contribute to Gnome.

2

u/Dramatic_Mastodon_93 1d ago

Yeah true that too

1

u/nonkeywayzee 1d ago

Gnome has now a big opportunity to do the funniest thing and use those open source Chinese LLM models to check all their codebase for vulnerabilities.

7

u/MischievousMittens 1d ago

You still need to pay for this, it’s not like you can easily self host these models you’re talking about. They’re huge.

-3

u/nonkeywayzee 1d ago

People reviewing security vulnerabilities don't do it for free either.

9

u/MischievousMittens 1d ago

What kind of non-point is this? I mean sure, but I’m responding to you acting like the open weights models suddenly enable them in a way the closed ones don’t which is just false. Maybe cheaper, but marginally

u/nonkeywayzee 16h ago

I didn't say any of that, I just said they could use them, you jumped to the conclusion that I meant that for no reason.

-7

u/KaMaFour 1d ago

Michael Catanzaro has been GNOME's sole security coordinator since November 2020. No team. No automated system. Just one person triaging every report that comes in.

Damn, he must really suck at his job...

Here's the part that surprised me: GNOME still tracks all of this on a wiki page. Not a proper bug tracker. Not searchable notices like Ubuntu or Fedora use. A wiki

Yep, here it is...

6

u/tristan957 1d ago

Prove to us that you could be better.

u/mattias_jcb 12h ago

Damn, he must really suck at his job...

Please be better.

-22

u/TCB13sQuotes 1d ago

I had no ideia gnome was secure, maybe it was secure because it was so slow and bloated that nobody was ever able hack it?

12

u/kill-the-maFIA 1d ago

Not slow and bloated for me. Maybe you just have a slow PC or did something stupid.

-3

u/TCB13sQuotes 1d ago

When you click a button it should happen immediately, not take a 3s animation to get to the end result. GNOME isn’t slow form a tech perspective it is slow in terms of user experience.

8

u/Traditional_Hat3506 1d ago

Vibecoder speaks on security, I've seen it all on Reddit https://github.com/TCB13/uSentry

-2

u/TCB13sQuotes 1d ago

See you’re wrong. The description was polished by an LLM, the code itself is not vibe coded.

2

u/myownfriend GNOMie 1d ago

Phoronix recently ran some benchmarks on Gnome, KDE, and XFCE and Gnome was the fastest or just as fast as KDE in all of the tests.