Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Ending the Free Lunch
Hal Flynn, 2003-11-26

Linux vendors spend money building security bug fixes. How much longer will they give them away for free?

Comments Mode:
Ending the Free Lunch 2003-11-26
Anonymous (1 replies)
The Cost of Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
The Cost of Ending the Free Lunch 2003-12-06
Anonymous
Ending the Free Lunch 2003-11-26
Rob McQuillen
Hal,
Interesting article, but I'm having difficulty believing that vendors, be they of free or commercial software, charging money for security fixes could be anything but bad news for an Internet that already enjoys Free Patches For All, yet is still ripe with security disasters.

It certainly makes sense from a business perspective: ABC Vendor's software doesn't come with any guarantees or warranty, so they're not legally obligated to fix their software. They devote resources towards fixing security holes and other bugs, and certainly don't make money giving away their work.

Apple's situation isn't a new one. The ISC raised a similar outburst a year or two ago when they wanted to start charging BIND users for timely security fixes. Not only did this delay deployment of fixes for those not fortunate enough or unwilling to pay, it gives a cracker who is willing to pay (or simply break into the system of a paying 'patch subscriber') a nice headstart on the rest of the world- he's now got plenty of detailed information on the vulnerability before most everyone else does.

BIND is a good example- how about a certain prolific operating system rife with security holes that begins with an 'M' and ends with an 'icrosoftWindows'? If Joe User doesn't patch his system because he's lazy and doesn't care, why in the world would he patch it when he's got a third reason not to (that directly affects his own pocketbook)?

If charging for patches becomes common practice, the already horrendous state of information security will be degraded even further. If software vendors find they are spending too much time/money on removing bugs from their software- tough luck. Perhaps that will convince them that it's high time to start building software securely and reliably from the outset.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/200/23895#23895
Lots of points missed... 2003-11-26
Penguinisto (2 replies)
Lots of points missed... 2003-12-01
Anonymous (1 replies)
Lots of points missed... 2003-12-01
Penguinisto
Lots of points missed... 2003-12-02
Anonymous (1 replies)
Lots of points missed... 2003-12-03
Penguinisto
Ending the Free Lunch 2003-11-27
Anonymous Coward
Ending the Free Lunch 2003-11-27
Anonymous (2 replies)
Ending the Free Lunch 2003-11-28
Anonymous (1 replies)
Ending the Free Lunch 2003-12-01
Anonymous
Ending the Free Lunch 2003-11-28
Anonymous
Apple no, Suse sure 2003-11-27
groovecat
Ending the Free Lunch 2003-11-27
Anonymous
Ending the Free Lunch 2003-11-27
cowbutt
Ending the Free Lunch 2003-11-27
Anonymous (2 replies)
Huh? 2003-11-28
OCG (2 replies)
Huh? 2003-11-30
Anonymous (1 replies)
Huh? 2003-12-01
Anonymous
Huh? 2003-11-30
Anonymous
Ending the Free Lunch 2003-11-29
Anonymous (2 replies)
Ending the Free Lunch 2003-12-02
trips
HEEE HEEE 2003-12-02
Anonymous
Filet Mignon 2003-11-28
Tomothy Millen
Missed the point quite a bit 2003-11-28
Anonymous (1 replies)
Missed the point quite a bit 2003-12-01
Anonymous (1 replies)
Missed the point quite a bit 2003-12-02
Anonymous
Ending the Free Lunch 2003-11-28
Anonymous (1 replies)
Ending the Free Lunch 2003-12-02
Anonymous
UH? 2003-11-30
Tripper
So wrong..... 2003-12-01
jmorris@beau.org
GPL - simple really 2003-12-01
Anonymous (1 replies)
GPL - simple really 2003-12-03
Anonymous
wrong 2003-12-01
Anonymous
Freedom, not Freeness 2003-12-01
Frihet
Ending the Free Lunch 2003-12-01
esjatharvee
Ending the Free Lunch 2003-12-01
Joseph Smith
Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
Ending the Free Lunch 2003-12-07
Anonymous
Ending the Free Lunch 2003-12-01
Anonymous
Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
Ending the Free Lunch 2003-12-02
Anonymous
Who actually fixes bugs? 2003-12-01
Anonymous (1 replies)
Who actually fixes bugs? 2003-12-03
Anonymous
Ending the Free Lunch 2003-12-01
Z2
Ending the Free Lunch (IT reporting) 2003-12-01
Anonymous (1 replies)
Jouro-Lobbiest 2003-12-01
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous (1 replies)
Ending the Free Lunch 2003-12-04
Anonymous
Lame article 2003-12-05
Anonymous
Ending the Free Lunch 2003-12-05
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus