Royce Williams on Nostr: The CopyFail announcement and handling is one of the least defender-supporting I ...
The CopyFail announcement and handling is one of the least defender-supporting I think I've ever seen.
Mitigations were extremely thin at launch, and haven't improved much, and are even brittle and misleading:
https://infosec.exchange/@tychotithonus/116490466168316767They've also largely neglected most of the value of the feedback they're getting from defenders clamoring for useful intel. The GitHub repo is full of feedback about which distros are affected or unaffected ... and a day later, none of it has been used to update the list of affected versions in the main README (except for the RHEL made-up version fix)
And this exchange is painful:
https://github.com/theori-io/copy-fail-CVE-2026-31431/issues/12"None of us are RH people so it wasn't caught" 😐 You had *weeks* do basic vetting, or find someone who would help you.
Theori seems to have to have intended this to be a showcase for their product. Instead, it has convinced me that I will *never* buy anything from them.
#CopyFail #cve_2026_31431
Published at
2026-04-30 13:38:24 UTCEvent JSON
{
"id": "9a539fedad2b0de52b91fc6668e1ceb488b4b2b482a4b5f4792c5f33da593b60",
"pubkey": "69647d5b8817472ac2ced4b88fd94dceb69e7cb0603872771a6737470a865e1d",
"created_at": 1777556304,
"kind": 1,
"tags": [
[
"t",
"cve_2026_31431"
],
[
"t",
"copyfail"
],
[
"proxy",
"https://infosec.exchange/@tychotithonus/116493930000105362",
"web"
],
[
"proxy",
"https://infosec.exchange/users/tychotithonus/statuses/116493930000105362",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://infosec.exchange/users/tychotithonus/statuses/116493930000105362",
"pink.momostr"
],
[
"-"
]
],
"content": "The CopyFail announcement and handling is one of the least defender-supporting I think I've ever seen. \n\nMitigations were extremely thin at launch, and haven't improved much, and are even brittle and misleading:\n\nhttps://infosec.exchange/@tychotithonus/116490466168316767\n\nThey've also largely neglected most of the value of the feedback they're getting from defenders clamoring for useful intel. The GitHub repo is full of feedback about which distros are affected or unaffected ... and a day later, none of it has been used to update the list of affected versions in the main README (except for the RHEL made-up version fix)\n\nAnd this exchange is painful: \n\nhttps://github.com/theori-io/copy-fail-CVE-2026-31431/issues/12\n\n\"None of us are RH people so it wasn't caught\" 😐 You had *weeks* do basic vetting, or find someone who would help you.\n\nTheori seems to have to have intended this to be a showcase for their product. Instead, it has convinced me that I will *never* buy anything from them.\n\n#CopyFail #cve_2026_31431",
"sig": "fe9f17a60ed2caf8207f74b6158c9d6a422b9676868ba9df84d162f74c410eed0f3c9f34e4e6d862824f12be167c998ab98983a936df0458578886bf467450d1"
}