Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 13 Jul 2000 21:25:15 -0600
From:      Brett Glass <brett@lariat.org>
To:        "Jeffrey J. Mountin" <jeff-ml@mountin.net>, "Jordan K. Hubbard" <jkh@zippy.osd.bsdi.com>
Cc:        security@FreeBSD.ORG
Subject:   Re: Displacement of Blame[tm] 
Message-ID:  <4.3.2.7.2.20000713211759.0585de60@localhost>
In-Reply-To: <4.3.2.20000713210451.00cf81c0@207.227.119.2>
References:  <4.3.2.7.2.20000713190150.04b9fc80@localhost> <2753.963529551@localhost> <Your message of "Thu, 13 Jul 2000 15:58:35 PDT." <Pine.BSF.4.21.0007131553420.38638-100000@neo.bleeding.com>

next in thread | previous in thread | raw e-mail | index | archive | help
At 08:57 PM 7/13/2000, Jeffrey J. Mountin wrote:

>In this case we are talking more about *your* clients and *their* 
>lack of education.

Well, that's why they hire me; because they don't want to have to
be extremely knowledgeable about computers! They're doctors and
lawyers, among other things, and Heaven knows there's enough
going on in their own fields to keep them busy.

>Frankly I don't understand why one would subscribe their customers 
>to a list for which they, obviously, are not qualified to evaluate 

For the same reason you might read a magazine that covers medical
issues and occasionally call up your doctor to ask, "Is this
something I should worrry about?"

>>The issue at hand here could really have an effect on FreeBSD's reputation
>>for security, so I hope you'll agree that this thread is worthwhile.
>
>In part I agree about the reputation, but if they don't read the complete advisory.  What's the use?

The use is that the skimmers will get a more accurate impression from their
skimming.

>Also consider charging them for your (wasted) time.  

I do. But they still have doubts, deep down, about the security of FreeBSD
after seeing all of these advisories which look like they MIGHT be FreeBSD
holes.

>Hopefully I didn't flame you too bad, but this kind of thread seems to bring everyone out with a different opinion and endless discussion that goes absolutely nowhere.  Tends to irk me more on -security than anything.

I never expected it to go on so long, actually. I figured that there would
be relatively quick consensus on a better format for the subject line.
So far, we've seen some good suggestions!

>Can't recall if it was mentioned by perhaps a very small change in the subject line:
>
>FreeBSD Ports Security Advisory <advisory #>.<port>
>
>to
>
>Port(s) Security Advisory (FreeBSD) <advisory #>.<port>

Yes, I like this. However, I'd put the name of the port FIRST, so it
looked more like:

<port> Security Advisory (From FreeBSD Security Team) <advisory number>

A little longer, but it's clearer.

--Brett



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4.3.2.7.2.20000713211759.0585de60>