, 2006-01-18
A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.
Expand all |
Post comment
How not to respond to a security advisory
2006-01-19
Miles (3 replies)
Miles (3 replies)

One of the reasons I (and others) use OpenBSD is that with OpenBSD we have a direct line to all levels of development. We don't have to deal with mindless tech support engineers or software developers who pass the buck without taking any responsibility for the product as a whole.
Anyone who's dealt with developers knows that you're also dealing with personalities. When you have a direct line to a developer, you're not going to get a smoothed out politicized response. This is particularly true with very creative people who are emotionally involved in their work.
One of the good things about OpenBSD is that, if you disagree, you can now take your issue up with Theo and the OpenBSD developers directly. Perhaps they'll see things your way after some discussion?
Personally, I'd rather have the rough-edged honesty of Theo than a nicely polished noncommital answer, or silence alltogether.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/380/33034#33034