Date: Sun, 16 Dec 2018 12:20:34 -0800 (PST) From: Roger Marquis <marquis@roble.com> To: Remko Lodder <remko@elvandar.org> Cc: freebsd-security@freebsd.org, ports-secteam@FreeBSD.org Subject: Re: SQLite vulnerability Message-ID: <nycvar.OFS.7.76.444.1812161119470.32121@mx.roble.com> In-Reply-To: <473172DA-7F1E-42EB-8E0B-53122E13E84E@elvandar.org> References: <nycvar.OFS.7.76.444.1812160753280.5993@mx.roble.com> <473172DA-7F1E-42EB-8E0B-53122E13E84E@elvandar.org>
next in thread | previous in thread | raw e-mail | index | archive | help
> It?s sad to see that you are still as negative as you where not that long > ago. Apologies for being negative Remko, but isn't it the implications for those running FreeBSD that are negative rather than someone pointing them out? Or do we have different interpretations of the scope or threat profile of this particular issue? (considering that sqlite has been installed by default on every FreeBSD host and jail for a few years now) > I said before that If you rely on the information being up to date, you > should sponsor the FF or pay someone to do the work for you. You keep > forgetting that we (security-officer@ and ports-secteam@) are volunteers > and that we do this in our free spare time. This is a good answer to my question regarding what might be done to address the gap in reporting. I am in no position to financially sponsor anyone but certainly the FreeBSD Foundation is. Maybe someone from the board could weigh-in regarding the feasibility of funding this critical function? According to <www.freebsdfoundation.org/about/financials/> more than $3M is available, a small portion of which, if applied on an ongoing basis, would bring FreeBSD up to the 3rd party application security standards of its competitors (Android aside) and make the OS infinitely easier for us to advocate, admin and develop for. On that note, does anyone on this list have experience applying for FreeBSD Foundation grants? If so please contact me off-list. OTOH it may also be a matter of team size and/or policies that would be more effective in the short term. Would be great if other sec team and or board members could comment (ideally without shooting the messenger). > I do not think the others need to step in for this one, your constant > negative attitude towards our ports-secteam people is getting annoying and > a waste of our precious time. So either start sending patches, contribute, > or understand that this is voluntarily and that their priorities might not > be your priority. I don't know Remko. It seems like too far-reaching of an issue to ignore. Most of us don't see it as negative or positive but simply a means of keeping end-users safe and making everyone's contribution to the project more effective. Roger Marquis
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?nycvar.OFS.7.76.444.1812161119470.32121>