On 03/15/2007 10:24:31 PM, Tony Abernethy wrote:All the security in the world does me no good if it's not installed on my systems. No. Yes. If I wasn't then there wouldn't be an errata would there? I track -STABLE, because I want relyability. I won't get the next unsung fix until an errata is announced that might affect me. I've better things to do than install new builds all the time. No, but if security errata announcements arn't delivered in a fashion that delivers them to a human then they do no good. I should not be expected to peruse the misc@openbsd.org list to find errata announcements. OpenBSD says announcements will be made on security-announce when patches become available. This did not happen. Ergo, something is broken. I can't fix it. It may not be fixable, but if it is fixable then it should be fixed. We should not all just pretend it didn't happen. If there is something that can be fixed I'd like to hear about it when it gets fixed. Hence my post. Further, it's important to let the OpenBSD project know how important the brokenness is. (Recall, I'm not talking about the security vulnerability, I'm talking about the communication breakdown.) If my clients hear about a OpenBSD vulnerability from the media, before I hear about it from OpenBSD, that's bad. I want them to hear about problems with their systems, however slight, from me (or directly from OpenBSD of course). I don't want clients to hear about problems on their systems from some media panic attack article. OpenBSD has always solicited feedback regards how important particular bugs are. Now you've the relevant information you can decide how high to jump. Regards, Karl <kop@meme.com> Free Software: "You don't pay back, you pay forward." -- Robert A. Heinlein
| Greg Kroah-Hartman | [PATCH 005/196] Chinese: add translation of SubmittingDrivers |
| Jeremy Fitzhardinge | [PATCH 10 of 36] x86: unify pgd_index |
| debian developer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Karsten Wiese | Re: 2.6.20-rc6-mm3 |
git: | |
| Steffen Prohaska | How to reduce remaining differences to 4msysgit? (was What's cooking in git.git (t... |
| Jakub Narebski | Re: Cleaning up git user-interface warts |
| Linus Torvalds | Re: git versus CVS (versus bk) |
| Johannes Sixt | [PATCH 12/40] Windows: Implement gettimeofday(). |
| Richard Stallman | Real men don't attack straw men |
| Maxim Belooussov | -current and rthreads |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Amarendra Godbole | Anyone from this list at BlackHat or DefCon? And a query... |
| David Willmore | Re: Intel, the Pentium and Linux |
| Theodore Ts'o | Re: demand paging: proposal |
| Lars Wirzenius | Re: Stabilizing Linux |
| Ari Lemmke | find-1.2 |
| Why Windows is better than Linux | 36 minutes ago | Linux general |
| magical mounts | 1 hour ago | Linux kernel |
| Problem in scim in Fedora 9 | 2 hours ago | Linux general |
| The new Western Digital power saving drives | 2 hours ago | Hardware |
| Battery Maximizer Software | 22 hours ago | Linux kernel |
| windows folder creation surprise | 1 day ago | Windows |
| Firewall | 1 day ago | OpenBSD |
| IP layer send packet | 2 days ago | Linux kernel |
| dtrace for linux available | 2 days ago | Linux kernel |
| Unable to mount ramdisk image using UBoot while upgrading to 2.6.15 kernel for a MPC8540 based target | 2 days ago | Linux kernel |
