login
Header Space

 
 

Re: Important OpenBSD errata

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Misc OpenBSD <misc@...>
Date: Friday, March 16, 2007 - 2:25 pm

On 3/16/07, Martin Schrvder <martin@oneiros.de> wrote:
[snip blah blah blah...]

After all the kvetching and sensationalism that's characterized both
this thread and the release of this errata, there's a few things I
wanted to point out. Theo's already put out the timeline and
circumstances around classification of reliability and later security
fix. Core Security also included the timeline in their advisory. The
first point to make is this: the fix was applied in a more-than-timely
manner. The errata was merged into -stable and made available March 7.
Core Security released their advisory March 13. That's very good lead
time, and that means the patch was available darn near a week before
the advisory came out. If people aren't checking the errata pages for
a week at a time, there's a larger issue than a lack of email
notification.

The second point relates to the natural dissent that the first point
invites; if the announcement doesn't go to the security announce list,
how are people supposed to know that the errata is available? I want
everyone trying to make that point to think of all the software
vendors they deal with, including the commercial software vendors to
whom you pay thousands (and depending on the size of your
organization, millions) of dollars to per year. Can you say that you
get SMTP notifications from all of them? The answer, if you're in any
situation resembling what I've been in for the last decade, is no. The
reality is, it's *not* an assumption that you'll get notifications
from anyone in your happy little inbox. Most of my current vendors
(lots of them, too) don't have any official vulnerability notification
channel in place, and when we approach them about it, they point us to
their web site support page where we can find updates as they are
released. The landscape for this kind of thing is awful, and in fact
OpenBSD is ahead of the curve here because they actually do admit and
respond to vulnerabilities in an open manner. Closed source,
commercial vendors hide it and sweep it under the rug.

As has been pointed out, you will have better success tracking other
sources such that you increase your chances of hearing about
vulnerability information before it's too late. source-changes is a
good option. Undeadly is nice. tech@ is a good one to lurk on. There's
an IRC channel. And of course, there's the collection of Internet
resources for vulnerability research information. If you're not
tracking things like bugtraq, full-disclosure, Dshield, CERT lists,
milw0rm, etc, etc, etc, then your problems (and your precious
customers' problems) are much bigger than a IPv6 vulnerability in
OpenBSD.

You can bitch about the security announce mailing list, or you can put
forth some effort to do something proactive yourself to get more
benefit from the free software you use. Those of us that were patched
before the advisory came out would probably say you're better off with
the latter.

DS
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 12:23 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 1:56 pm)
Re: Important OpenBSD errata, Kyle George, (Mon Mar 19, 4:07 pm)
Re: Important OpenBSD errata, Travers Buda, (Fri Mar 16, 1:51 am)
Re: Important OpenBSD errata , Theo de Raadt, (Fri Mar 16, 12:29 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 2:08 pm)
Re: Important OpenBSD errata, Shawn K. Quinn, (Sun Mar 18, 1:25 am)
Re: Important OpenBSD errata, Shane J Pearson, (Sun Mar 18, 5:14 am)
Re: Important OpenBSD errata, Nico Meijer, (Sat Mar 17, 3:03 pm)
Re: Important OpenBSD errata , Theo de Raadt, (Sat Mar 17, 2:18 pm)
Re: Important OpenBSD errata, Martin Schröder, (Fri Mar 16, 5:32 am)
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 1:06 am)
Re: Important OpenBSD errata, Jacob Yocom-Piatt, (Fri Mar 16, 1:49 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 2:47 pm)
Re: Important OpenBSD errata, Travers Buda, (Sat Mar 17, 9:43 pm)
Re: Important OpenBSD errata, Jack J. Woehr, (Sat Mar 17, 11:05 pm)
Re: Important OpenBSD errata, tony sarendal, (Fri Mar 16, 2:03 am)
Re: Important OpenBSD errata, Travers Buda, (Fri Mar 16, 2:49 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 3:09 pm)
Re: Important OpenBSD errata, Ben Calvert, (Sat Mar 17, 4:16 pm)
Re: Important OpenBSD errata, tony sarendal, (Fri Mar 16, 4:15 am)
Re: Important OpenBSD errata, Travers Buda, (Fri Mar 16, 11:34 am)
Re: Important OpenBSD errata, Greg Thomas, (Fri Mar 16, 11:55 am)
Re: Important OpenBSD errata, Sunnz, (Fri Mar 16, 3:34 am)
Re: Important OpenBSD errata, Lars Hansson, (Fri Mar 16, 2:32 am)
Re: Important OpenBSD errata, Martin Schröder, (Fri Mar 16, 5:30 am)
Re: Important OpenBSD errata, Darren Spruell, (Fri Mar 16, 2:25 pm)
Re: Important OpenBSD errata, Woodchuck, (Sat Mar 17, 3:52 pm)
Re: Important OpenBSD errata , Theo de Raadt, (Sat Mar 17, 4:52 pm)
Re: Important OpenBSD errata, Richard Thornton, (Fri Mar 16, 6:22 am)
Re: Important OpenBSD errata , Theo de Raadt, (Fri Mar 16, 7:40 am)
Re: Important OpenBSD errata, fonkprop, (Fri Mar 16, 8:43 pm)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 4:00 pm)
Re: Important OpenBSD errata, Ray Percival, (Sat Mar 17, 5:22 pm)
Re: Important OpenBSD errata, Ray Percival, (Fri Mar 16, 9:57 pm)
Re: Important OpenBSD errata, Siegbert Marschall, (Sat Mar 17, 12:39 pm)
Re: Important OpenBSD errata, Sunnz, (Fri Mar 16, 10:30 pm)
Re: Important OpenBSD errata, Jeremy Huiskamp, (Fri Mar 16, 10:20 pm)
Re: Important OpenBSD errata, Lars Hansson, (Fri Mar 16, 6:54 am)
Re: Important OpenBSD errata, Sunnz, (Fri Mar 16, 3:03 am)
Re: Important OpenBSD errata, Lars Hansson, (Fri Mar 16, 3:28 am)
Re: Important OpenBSD errata, Sunnz, (Fri Mar 16, 4:09 am)
Re: Important OpenBSD errata, Kian Mohageri, (Fri Mar 16, 3:51 am)
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 9:24 am)
Re: Important OpenBSD errata, Martin Schröder, (Fri Mar 16, 9:56 am)
Re: Important OpenBSD errata, Martin Schröder, (Fri Mar 16, 5:26 am)
Re: Important OpenBSD errata, Daniel Ouellet, (Fri Mar 16, 1:40 am)
Re: Important OpenBSD errata, Karel Kulhavy, (Sat Mar 17, 2:33 pm)
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 2:03 am)
Re: Important OpenBSD errata, Karl O. Pinc, (Fri Mar 16, 1:57 am)
speck-geostationary