Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
How not to respond to a security advisory
Jason Miller, 2006-01-18

A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.

Comments Mode:
How not to respond to a security advisory 2006-01-19
Anonymous (1 replies)
Linux security contact 2006-01-19
Anonymous
Theo being theo... 2006-01-19
Anonymous (2 replies)
Re: Theo being theo... 2006-01-20
Anonymous
What total nonsense. 2006-01-19
Anonymous
"Root problem" again 2006-01-24
Alexey Vesnin
How not to respond to a security advisory 2006-01-25
Michael Favinsky (1 replies)
OpenBSD is one of the few production-grade UN*X projects in existence where you, as an end user, have a direct line to the OS developers, where the developers actually read your email and take the time to respond. You don't get this privilege with Microsoft, and you definitely don't get this privilege with Linux. When's the last time you got to speak to an actual software engineer at Microsoft? When's the last time Linus Torvalds responded to an issue you had with some version of Linux?

One of the reasons I (and others) use OpenBSD is that with OpenBSD we have a direct line to all levels of development. We don't have to deal with mindless tech support engineers or software developers who pass the buck without taking any responsibility for the product as a whole.

Anyone who's dealt with developers knows that you're also dealing with personalities. When you have a direct line to a developer, you're not going to get a smoothed out politicized response. This is particularly true with very creative people who are emotionally involved in their work.

One of the good things about OpenBSD is that, if you disagree, you can now take your issue up with Theo and the OpenBSD developers directly. Perhaps they'll see things your way after some discussion?

Personally, I'd rather have the rough-edged honesty of Theo than a nicely polished noncommital answer, or silence alltogether.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/380/33034#33034
this is a non-issue 2006-02-04
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus