|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Subject: Re: Two kinds of advisories?
From: Kris Kennaway (kris
FreeBSD.org)Date: Thu Jul 13 2000 - 20:42:22 CDT
- Next message: Andrew Kenneth Milton: "Re: Displacement of Blame[tm]"
- Previous message: Brett Glass: "Re: Displacement of Blame[tm]"
- In reply to: Frank Tobin: "Re: Two kinds of advisories?"
- Next in thread: Robert Watson: "Re: Two kinds of advisories?"
- Next in thread: Justin Wolf: "Displacement of Blame[tm]"
- Reply: Kris Kennaway: "Re: Two kinds of advisories?"
- Reply: Robert Watson: "Re: Two kinds of advisories?"
- Reply: Warner Losh: "Re: Two kinds of advisories?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Thu, 13 Jul 2000, Frank Tobin wrote:
> Kris Kennaway, at 13:44 -0700 on Thu, 13 Jul 2000, wrote:
>
> > "Ports" is already in the subject. If someone doesn't know what "Ports"
> > means, how will changing the advisory numbering make any difference?
>
> Because management won't know what "Ports" means, but will make decisions
> about the use of FreeBSD irregardless of whether the advisory is really
> for FreeBSD.
Turn this to your advantage: we acknowledge and fix our security bugs in
public, and those in software we ship, regardless of how embarrassing they
may be, because we care about the security of our users. The majority of
these holes are also present in other OSes, many of whom do not bother to
ackowledge them (as) publically.
This is already apparent from the "FreeBSD only: NO" in most of the 33
advisories this year, but it's not professional to name the other
platforms explicitly (besides the fact that we can't always be sure, as I
learned once the hard way when I overestimated the severity of a NetBSD
vulnerability).
In other words, this is an advocacy issue, not one which can be magically
fixed by cramming more into the subject line of advisories. I'm not one to
blow my own horn, but it's the kind of thing which might make a good
article or two to get this point across to the world and provide something
to point to when people make that claim.
As long as I'm the one writing these advisories I'm not going to do
anything to make them less visible to the wider community - I want it to
be known that a) FreeBSD fixes its security vulnerabilities and tells
people when we do, and b) there is an awful lot of bad code out there
which hurts *EVERYONE*, not just FreeBSD.
I see myself as providing a service to a larger community than just
FreeBSD users here precisely because these advisories are widely
distributed, and (compared to what other vendors produce) more informative
- in fact I've gotten feedback from people who don't even use FreeBSD who
have been impressed by this.
I am trying to build FreeBSD's reputation as an OS which takes security
damn seriously, and so far I think I've had at least moderate success.
Kris
--
In God we Trust -- all others must submit an X.509 certificate.
-- Charles Forsythe <forsythe
alum.mit.edu>
To Unsubscribe: send mail to majordomo
FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message
- Next message: Andrew Kenneth Milton: "Re: Displacement of Blame[tm]"
- Previous message: Brett Glass: "Re: Displacement of Blame[tm]"
- In reply to: Frank Tobin: "Re: Two kinds of advisories?"
- Next in thread: Robert Watson: "Re: Two kinds of advisories?"
- Next in thread: Justin Wolf: "Displacement of Blame[tm]"
- Reply: Kris Kennaway: "Re: Two kinds of advisories?"
- Reply: Robert Watson: "Re: Two kinds of advisories?"
- Reply: Warner Losh: "Re: Two kinds of advisories?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]