login
Header Space

 
 

Re: Important OpenBSD errata

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Tony Abernethy <tony@...>
Cc: 'Martin Schröder' <martin@...>, 'Misc OpenBSD' <misc@...>, <deraadt@...>
Date: Friday, March 16, 2007 - 12:23 am

On 03/15/2007 10:24:31 PM, Tony Abernethy wrote:





All the security in the world does me no good
if it's not installed on my systems.


No.


Yes.  If I wasn't then there wouldn't be
an errata would there?


I track -STABLE, because I want relyability.  I won't
get the next unsung fix until an errata is announced
that might affect me.  I've better things to do
than install new builds all the time.


No, but if security errata announcements arn't delivered
in a fashion that delivers them to a human then they
do no good.  I should not be expected to peruse the
misc@openbsd.org list to find errata announcements.
OpenBSD says announcements will be made on security-announce
when patches become available.  This did not happen.
Ergo, something is broken.  I can't fix it.  It may
not be fixable, but if it is fixable then it should
be fixed.  We should not all just pretend it didn't
happen.  If there is something that
can be fixed I'd like to hear about it when it
gets fixed.  Hence my post.

Further, it's important to let the OpenBSD project
know how important the brokenness is.  (Recall,
I'm not talking about the security vulnerability,
I'm talking about the communication breakdown.)
If my clients hear about a OpenBSD vulnerability
from the media, before I hear about it from
OpenBSD, that's bad.  I want them to hear about
problems with their systems, however slight, from
me (or directly from OpenBSD of course).  I don't
want clients to hear about problems on their systems
from some media panic attack article.

OpenBSD has always solicited feedback regards
how important particular bugs are.
Now you've the relevant information you
can decide how high to jump.

Regards,

Karl <kop@meme.com>
Free Software:  "You don't pay back, you pay forward."
                  -- Robert A. Heinlein
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 12:23 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 1:56 pm)
Re: Important OpenBSD errata, Kyle George, (Mon Mar 19, 4:07 pm)
Re: Important OpenBSD errata, Travers Buda, (Fri Mar 16, 1:51 am)
Re: Important OpenBSD errata , Theo de Raadt, (Fri Mar 16, 12:29 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 2:08 pm)
Re: Important OpenBSD errata, Shawn K. Quinn, (Sun Mar 18, 1:25 am)
Re: Important OpenBSD errata, Shane J Pearson, (Sun Mar 18, 5:14 am)
Re: Important OpenBSD errata, Nico Meijer, (Sat Mar 17, 3:03 pm)
Re: Important OpenBSD errata , Theo de Raadt, (Sat Mar 17, 2:18 pm)
Re: Important OpenBSD errata, Martin Schröder, (Fri Mar 16, 5:32 am)
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 1:06 am)
Re: Important OpenBSD errata, Jacob Yocom-Piatt, (Fri Mar 16, 1:49 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 2:47 pm)
Re: Important OpenBSD errata, Travers Buda, (Sat Mar 17, 9:43 pm)
Re: Important OpenBSD errata, Jack J. Woehr, (Sat Mar 17, 11:05 pm)
Re: Important OpenBSD errata, tony sarendal, (Fri Mar 16, 2:03 am)
Re: Important OpenBSD errata, Travers Buda, (Fri Mar 16, 2:49 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 3:09 pm)
Re: Important OpenBSD errata, Ben Calvert, (Sat Mar 17, 4:16 pm)
Re: Important OpenBSD errata, tony sarendal, (Fri Mar 16, 4:15 am)
Re: Important OpenBSD errata, Travers Buda, (Fri Mar 16, 11:34 am)
Re: Important OpenBSD errata, Greg Thomas, (Fri Mar 16, 11:55 am)
Re: Important OpenBSD errata, Sunnz, (Fri Mar 16, 3:34 am)
Re: Important OpenBSD errata, Lars Hansson, (Fri Mar 16, 2:32 am)
Re: Important OpenBSD errata, Martin Schröder, (Fri Mar 16, 5:30 am)
Re: Important OpenBSD errata, Darren Spruell, (Fri Mar 16, 2:25 pm)
Re: Important OpenBSD errata, Woodchuck, (Sat Mar 17, 3:52 pm)
Re: Important OpenBSD errata , Theo de Raadt, (Sat Mar 17, 4:52 pm)
Re: Important OpenBSD errata, Richard Thornton, (Fri Mar 16, 6:22 am)
Re: Important OpenBSD errata , Theo de Raadt, (Fri Mar 16, 7:40 am)
Re: Important OpenBSD errata, fonkprop, (Fri Mar 16, 8:43 pm)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 4:00 pm)
Re: Important OpenBSD errata, Ray Percival, (Sat Mar 17, 5:22 pm)
Re: Important OpenBSD errata, Ray Percival, (Fri Mar 16, 9:57 pm)
Re: Important OpenBSD errata, Siegbert Marschall, (Sat Mar 17, 12:39 pm)
Re: Important OpenBSD errata, Sunnz, (Fri Mar 16, 10:30 pm)
Re: Important OpenBSD errata, Jeremy Huiskamp, (Fri Mar 16, 10:20 pm)
Re: Important OpenBSD errata, Lars Hansson, (Fri Mar 16, 6:54 am)
Re: Important OpenBSD errata, Sunnz, (Fri Mar 16, 3:03 am)
Re: Important OpenBSD errata, Lars Hansson, (Fri Mar 16, 3:28 am)
Re: Important OpenBSD errata, Sunnz, (Fri Mar 16, 4:09 am)
Re: Important OpenBSD errata, Kian Mohageri, (Fri Mar 16, 3:51 am)
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 9:24 am)
Re: Important OpenBSD errata, Martin Schröder, (Fri Mar 16, 9:56 am)
Re: Important OpenBSD errata, Martin Schröder, (Fri Mar 16, 5:26 am)
Re: Important OpenBSD errata, Daniel Ouellet, (Fri Mar 16, 1:40 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 2:33 pm)
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 2:03 am)
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 1:57 am)
speck-geostationary