Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
How not to respond to a security advisory
Jason Miller, 2006-01-18

A recently announced weakness in the BSD securelevel system isn't going to be fixed in OpenBSD. While securelevel may have problems, the vendor's security response is unacceptable and doesn't fit with their stated goals.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Re: Secure levels as a control is too coarse grained 2006-01-21
Anonymous
All true, but you're re-itterating points that the article agrees with.

The article isn't defending securelevels as useful or highly secure. It's simply saying they should either be fixed, or removed.

A crude, unqualified "won't fix because it is useless" is a bad position to take here. If it...

[ more ]  





 

Privacy Statement
Copyright 2008, SecurityFocus