OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Dailydave] [Full-disclosure] Linux's unofficial security-through-coverup policy

From: Thomas Ptacek (tqbfmatasano.com)
Date: Fri Jul 18 2008 - 10:49:58 CDT


> And Linus's point is that many of those regressions matter *more* than most
> security bugs, because they can totally hose your system too - corrupt
> filesystems, cause system hangs and lockups, poor performance, and who knows
> what else.

And this is where Linus lapses into crazy talk, because data
corruption bugs are far less important than vulnerabilities that can
compromise my mom's credit card numbers and bank accounts. Bugs don't
have adversaries. Vulnerabilities do.

But I feel Linus' pain.

--
---
Thomas H. Ptacek // matasano security
read us on the web: http://www.matasano.com/log
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave