Re: [stable] Linux 2.6.25.10

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Linus Torvalds <torvalds@...>
Cc: <pageexec@...>, Greg KH <greg@...>, Andrew Morton <akpm@...>, <linux-kernel@...>, <stable@...>
Date: Tuesday, July 15, 2008 - 7:34 pm

Linus Torvalds wrote:

The only plausible solution people have found to this problem is
"letting the world know", so everyone involved in the different stages
of IT maintenance can do their part and properly spread the solution
throughout the assets.

Unless you have a better idea, the full-disclosure policy must remain or
we're going back into 1992AD -- except the threats are thereof 2008.


Either someone classify and inform it as it is, a *security problem*, or 
the issue is likely to pass unnoticed by the majority or to not receive 
the necessary attention by the involved parts.

Right. You don't want your developers to be responsible for classifying 
bugs towards security. Fine. Even though my intuition and personal 
experience tell that the question must be approached by those deeply 
involved in the development life-cycle, which, on their side, are 
responsible for finding, classifying, advising and fixing the security 
issues. This seems appropriate. Further, this appears to be what the big 
software houses nowadays do: from early design and development stages, 
have people to [security] review their applications before deployment, 
up to giving high attention and adequate support to any reported 
security problem, afterwards release. Maybe this is all silly and the 
world is swimming in the wrong direction.

Opinions apart, what really matters: we have an ultimate declaration 
about Linus' tree -- we may forget the pre-official (?) announcement 
[Documentation/SecurityBugs] and know that someone else must, 
eventually, classify and inform the world about security bugs existent 
in their software.
 From our consumer side, every time an issue of this nature is found, 
let's pray for some intermediate, gray, angel to send us an "warning" 
message.


Not more I can do but to make sure that all my peers are informed of 
such a grave reality.

Sincerely,
Tiago


--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Linux 2.6.25.10, Greg KH, (Wed Jul 2, 11:58 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Thu Jul 3, 1:08 pm)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 1:29 pm)
Re: Linux 2.6.25.10, Bart Van Assche, (Sat Jul 5, 3:54 am)
Re: Linux 2.6.25.10, Greg KH, (Tue Jul 8, 12:12 am)
Re: Linux 2.6.25.10, Greg KH, (Thu Jul 3, 2:57 pm)
Re: Linux 2.6.25.10, , (Thu Jul 3, 3:31 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Mon Jul 14, 8:04 am)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 8:47 pm)
RE: [stable] Linux 2.6.25.10, , (Fri Jul 18, 9:01 pm)
RE: [stable] Linux 2.6.25.10, David Schwartz, (Fri Jul 18, 9:51 pm)
Re: [stable] Linux 2.6.25.10, Willy Tarreau, (Sat Jul 19, 1:41 am)
Re: [stable] Linux 2.6.25.10, , (Mon Jul 14, 10:14 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Mon Jul 14, 10:27 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 4:15 pm)
Re: [stable] Linux 2.6.25.10, Bernd Eckenfels, (Sat Jul 19, 9:13 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:34 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 11:31 am)
Re: [stable] Linux 2.6.25.10, Theodore Tso, (Tue Jul 15, 2:33 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 4:28 pm)
Re: [stable] Linux 2.6.25.10, Greg KH, (Tue Jul 15, 6:39 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:09 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 6:47 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:22 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 7:35 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:08 pm)
Re: [stable] Linux 2.6.25.10, David Miller, (Tue Jul 15, 7:21 pm)
Re: [stable] Linux 2.6.25.10, Tiago Assumpcao, (Tue Jul 15, 7:26 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 7:26 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:07 pm)
Re: [stable] Linux 2.6.25.10, , (Tue Jul 15, 3:03 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 3:16 pm)
Re: [stable] Linux 2.6.25.10, Linus Torvalds, (Tue Jul 15, 12:13 pm)
Re: [stable] Linux 2.6.25.10, Aidan Thornton, (Thu Jul 17, 5:08 pm)
Re: Linux 2.6.25.10, Greg KH, (Wed Jul 2, 11:58 pm)