Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Ending the Free Lunch
Hal Flynn, 2003-11-26

Linux vendors spend money building security bug fixes. How much longer will they give them away for free?

Comments Mode:
Ending the Free Lunch 2003-11-26
Anonymous (1 replies)
The Cost of Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
The Cost of Ending the Free Lunch 2003-12-06
Anonymous
Ending the Free Lunch 2003-11-26
Rob McQuillen
Lots of points missed... 2003-11-26
Penguinisto (2 replies)
Lots of points missed... 2003-12-01
Anonymous (1 replies)
Lots of points missed... 2003-12-01
Penguinisto
Lots of points missed... 2003-12-02
Anonymous (1 replies)
Lots of points missed... 2003-12-03
Penguinisto
Ending the Free Lunch 2003-11-27
Anonymous Coward
Ending the Free Lunch 2003-11-27
Anonymous (2 replies)
Ending the Free Lunch 2003-11-28
Anonymous (1 replies)
Ending the Free Lunch 2003-12-01
Anonymous
Ending the Free Lunch 2003-11-28
Anonymous
Apple no, Suse sure 2003-11-27
groovecat
Ending the Free Lunch 2003-11-27
Anonymous
Ending the Free Lunch 2003-11-27
cowbutt
I'm sorry, but this article is almost completely oblivious of the way security issues are found and quashed within Free and Open Source software.

Unlike proprietary software, typically the flaws are found by the developers themselves and the fixes rolled into the canonical release (the "upstream" as distro vendors call it), or the discoverers of the vulnerability include the patch in their advisory. The Debian project is also a major source of security fixes for all distros. In my experience, the vendors rarely create the patch themselves - relying instead upon the above-defined "community" and their mailing lists to do so.

The value that the vendors add is creating an easy-to-install, tested, binary packages, and sometimes, in the case of more conservative distros such as Red Hat and Debian, "backporting" the fix from the current version to older versions of packages shipped (so as to reduce the risk of the update package causing breakages elsewhere in the system - a la Microsoft).

Red Hat are already charging for subscriptions to their convenient Red Hat Network service, though it's possible to get their errata (arguably) less conveniently from ftp.redhat.com and its mirrors for free. I would not be surprised if the update /BINARIES/ eventually disappeared from ftp.redhat.com, but they'd almost certainly have to continue publically distributing the individual patches and build instructions in order to comply with the terms of the GPL. If they don't, they lose their right to distribute all GPL code (which would be fatal for a company like Red Hat). It is conceivable that they could refrain from doing so for non-GPL packages such as XFree86 and Apache.

As it happens, the most convenient way for Red Hat to distribute the patches and build instructions is probably in the form of their src.rpms, which can be easily rebuilt to produce binary packages, though some users will be wary of doing this and will WANT to pay for access to the "official" binary updates. Also, it is quite workable for large-ish organisations or specialist consultancies to take the original distro-supplied source packages and the community-supplied patches and use them to create new binary update packages independent of the distro vendors.

Finally, if you carefully examine the pricing of Red Hat's Enterprise releases, the software still costs nothing - the costs are entirely for access to the Red Hat Network and, optionally, individual support. Red Hat have not dropped their desktop distro - they still offer RHEL WS (workstation). Red Hat are also quite open to admit that they'll discount the RHN and support pricing for large (i.e. profitable and probably more knowledgable) customers.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/200/23911#23911
Ending the Free Lunch 2003-11-27
Anonymous (2 replies)
Huh? 2003-11-28
OCG (2 replies)
Huh? 2003-11-30
Anonymous (1 replies)
Huh? 2003-12-01
Anonymous
Huh? 2003-11-30
Anonymous
Ending the Free Lunch 2003-11-29
Anonymous (2 replies)
Ending the Free Lunch 2003-12-02
trips
HEEE HEEE 2003-12-02
Anonymous
Filet Mignon 2003-11-28
Tomothy Millen
Missed the point quite a bit 2003-11-28
Anonymous (1 replies)
Missed the point quite a bit 2003-12-01
Anonymous (1 replies)
Missed the point quite a bit 2003-12-02
Anonymous
Ending the Free Lunch 2003-11-28
Anonymous (1 replies)
Ending the Free Lunch 2003-12-02
Anonymous
UH? 2003-11-30
Tripper
So wrong..... 2003-12-01
jmorris@beau.org
GPL - simple really 2003-12-01
Anonymous (1 replies)
GPL - simple really 2003-12-03
Anonymous
wrong 2003-12-01
Anonymous
Freedom, not Freeness 2003-12-01
Frihet
Ending the Free Lunch 2003-12-01
esjatharvee
Ending the Free Lunch 2003-12-01
Joseph Smith
Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
Ending the Free Lunch 2003-12-07
Anonymous
Ending the Free Lunch 2003-12-01
Anonymous
Ending the Free Lunch 2003-12-01
Anonymous (1 replies)
Ending the Free Lunch 2003-12-02
Anonymous
Who actually fixes bugs? 2003-12-01
Anonymous (1 replies)
Who actually fixes bugs? 2003-12-03
Anonymous
Ending the Free Lunch 2003-12-01
Z2
Ending the Free Lunch (IT reporting) 2003-12-01
Anonymous (1 replies)
Jouro-Lobbiest 2003-12-01
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous
Ending the Free Lunch 2003-12-02
Anonymous (1 replies)
Ending the Free Lunch 2003-12-04
Anonymous
Lame article 2003-12-05
Anonymous
Ending the Free Lunch 2003-12-05
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus