Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 9 Jul 2008 13:27:06 -0400
From:      "Josh Mason" <wtf.matters@gmail.com>
To:        "Remko Lodder" <remko@freebsd.org>
Cc:        freebsd-security@freebsd.org, astorms@ncircle.com
Subject:   Re: BIND update?
Message-ID:  <17cd1fbe0807091027n6af312cbwab3d3277f2b5e081@mail.gmail.com>
In-Reply-To: <4874F149.1040101@FreeBSD.org>
References:  <17cd1fbe0807090819o2aa28250h13c58dbe262abb7c@mail.gmail.com> <3a558cb8f79e923db0c6945830834ba2.squirrel@galain.elvandar.org> <17cd1fbe0807090909i566e1789s6b7b61bf82dd333e@mail.gmail.com> <4874ECDA.60202@elvandar.org> <4874F149.1040101@FreeBSD.org>

next in thread | previous in thread | raw e-mail | index | archive | help
On 7/9/08, Remko Lodder <remko@freebsd.org> wrote:
> Remko Lodder wrote:
> > Josh Mason wrote:
> >
> > Thanks, you really showed how you are by sending these replies. I wish you
> goodluck with your quest, perhaps someday someone can help you.
> >
> > Goodbye.
> >
> >
>
> Hi,
>
> I am sorry for this reply, it was an expression of my frustation towards
> you. The frustation is just easily generated by people demanding support
> from volunteers, that are trying to service you and others in their own
> spare time. Time that they can also spend on different items, yet we
> crazy people decide to work on a Free Operating System, getting nothing
> payed for it, only happy users (Where possible) around us.
>
> I think you can understand my frustration, because I think you would reply
> the same if someone demanded even more free time from you.
>
> I hope you can understand this.
>
> //Remko
>

I completely understand and took no offence from your previous email -
I know I am being confrontational. I myself have been in that position
many a time before and know exactly how it feels. Unfortunately that
doesn't negate the responsibility of the security team to produce
patches quickly.

The initial response of "the sec team is aware of the situation and
will investigate" was basically just fluff. If you weren't already
aware of it you aren't much of a sec team. What is needed is an
expected delivery. I would say considering the nature of the exploit
but honestly that shouldn't change anything at all. If the delivery
isn't going to be immediate there should always be an ETA provided. If
for nothing else other than so your users can plan around it (i.e.
"this is too long I need to take action myself" - "or X time or date
is sufficient I'll wait for the official release and apply it then").
Without that people are twiddling their thumbs wondering if there is
ever going to be one.

      Josh



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?17cd1fbe0807091027n6af312cbwab3d3277f2b5e081>