BugTraq
Re: DJB's students release 44 *nix software vulnerability advisories Dec 18 2004 04:25AM
D. J. Bernstein (djb cr yp to) (2 replies)
Re: DJB's students release 44 *nix software vulnerability advisories Dec 21 2004 07:39PM
Stephen Samuel (samuel bcgreen com) (1 replies)
Re: DJB's students release 44 *nix software vulnerability advisories Dec 22 2004 07:05AM
D. J. Bernstein (djb cr yp to) (2 replies)
Re: DJB's students release 44 *nix software vulnerability advisories Dec 22 2004 06:32PM
David Eisner (cradle umd edu)
Re: DJB's students release 44 *nix software vulnerability advisories Dec 22 2004 06:26PM
Crispin Cowan (crispin immunix com) (1 replies)
Re: DJB's students release 44 *nix software vulnerability advisories Dec 23 2004 06:39AM
D. J. Bernstein (djb cr yp to) (1 replies)
Re: DJB's students release 44 *nix software vulnerability advisories Dec 24 2004 09:29AM
Crispin Cowan (crispin immunix com)
Re: DJB's students release 44 *nix software vulnerability advisories Dec 21 2004 04:53PM
Artem Chuprina (ran ran pp ru)
D. J. Bernstein -> bugtraq (at) securityfocus (dot) com [email concealed] @ 18 Dec 2004 04:25:11 -0000:

>> In each case, Professor Bernstein notified the author of the
>> vulnerable package on Dec 15 via e-mail. This mail hit Bugtraq on the
>> 16th, giving one day for vendors to provide fixes.

DJB> Actually, I sent all of these notifications to the public
DJB> securesoftware mailing list (http://securesoftware.list.cr.yp.to)
DJB> at the same time that I sent them to the authors. It certainly
DJB> wasn't my intention to give the authors an extra day of
DJB> self-delusion.

Was it your intention not to give _users_ of their programs an extra
time of not being _widely_ attacked? While you certainly cannot offer
them alternative software for their tasks - of your own programs only
ezmlm with third-party patches is more than proof of concept. We need
software that does the work, not only one that demonstrates that the
work can be done in principle.

--
Artem Chuprina
RFC2822: <ran{}ran.pp.ru> Jabber: ran (at) jabber.ran.pp (dot) ru [email concealed]

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus