Re: The state of linux security

!MAILaRCHIVE_VOTE_RePLACE
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Cheradenine Zakalwe <sc.contact@...>
Cc: <linux-kernel@...>
Date: Wednesday, July 16, 2008 - 12:38 pm

On Wed, 16 Jul 2008, Cheradenine Zakalwe wrote:


how can you tell for sure if a bug has security implications or not?

the argument can be made that just about any bug can be a security bug

frequently the security implications of a bug are not known at the time 
it's fixed, but are discovered later. how do you expect to have this in 
the announcements?

if you only upgrade when there is a 'security bug' announcement you will 
miss a lot of important upgrades.

as Linus stated, there's nothing preventing anyone who thinks that he's 
not doing an appropriate job from doing the research on the security 
implications of everything and doing their own announcements or just 
maintaining their own tree.

David Lang
--
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
The state of linux security, Cheradenine Zakalwe, (Wed Jul 16, 12:05 pm)
Re: The state of linux security, Helge Hafting, (Sun Jul 20, 7:01 am)
Re: The state of linux security, Alan Cox, (Wed Jul 16, 1:57 pm)
Re: The state of linux security, Stefan Roas, (Wed Jul 16, 4:29 pm)
Re: The state of linux security, , (Wed Jul 16, 4:08 pm)
Re: The state of linux security, David Newall, (Wed Jul 16, 12:38 pm)
Re: The state of linux security, , (Wed Jul 16, 12:38 pm)
Re: The state of linux security, Randy Dunlap, (Wed Jul 16, 12:26 pm)