Red Hat's @kurtseifried thinks that 200 hours of brute force is a defense failure. smells like sour grapes for having ignored the problem.
2
4
e.g., grsec's brute force prevention had to be disabled to be able to trigger the bug at all. PaX doesn't have such by design.

Jun 19, 2017 · 3:55 PM UTC