Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
How not to respond to a security advisory
Jason Miller, 2006-01-18

A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.

Comments Mode:
How not to respond to a security advisory 2006-01-19
Anonymous
I keep track of the OpenBSD mailing list. Unfortunately, this attitude is quite normal for Theo and it has spread to several of the other developers as well. If securelevels are so useless, why hasn't the OpenBSD team designed a better solution? I'm sure they'd give numerous reasons why. Until a better solution comes along, I'll stick to using securelevels, along with other tools, to help secure my *BSD systems.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/380/32965#32965
How not to respond to a security advisory 2006-01-19
Anonymous (1 replies)
Linux security contact 2006-01-19
Anonymous
Theo being theo... 2006-01-19
Anonymous (2 replies)
Re: Theo being theo... 2006-01-20
Anonymous
What total nonsense. 2006-01-19
Anonymous
"Root problem" again 2006-01-24
Alexey Vesnin
How not to respond to a security advisory 2006-01-25
Michael Favinsky (1 replies)
this is a non-issue 2006-02-04
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus