Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 16 Dec 2018 12:20:34 -0800 (PST)
From:      Roger Marquis <marquis@roble.com>
To:        Remko Lodder <remko@elvandar.org>
Cc:        freebsd-security@freebsd.org, ports-secteam@FreeBSD.org
Subject:   Re: SQLite vulnerability
Message-ID:  <nycvar.OFS.7.76.444.1812161119470.32121@mx.roble.com>
In-Reply-To: <473172DA-7F1E-42EB-8E0B-53122E13E84E@elvandar.org>
References:  <nycvar.OFS.7.76.444.1812160753280.5993@mx.roble.com> <473172DA-7F1E-42EB-8E0B-53122E13E84E@elvandar.org>

next in thread | previous in thread | raw e-mail | index | archive | help
> It?s sad to see that you are still as negative as you where not that long
> ago.

Apologies for being negative Remko, but isn't it the implications for
those running FreeBSD that are negative rather than someone pointing
them out?  Or do we have different interpretations of the scope or
threat profile of this particular issue?  (considering that sqlite has
been installed by default on every FreeBSD host and jail for a few years
now)

> I said before that If you rely on the information being up to date, you
> should sponsor the FF or pay someone to do the work for you. You keep
> forgetting that we (security-officer@ and ports-secteam@) are volunteers
> and that we do this in our free spare time.

This is a good answer to my question regarding what might be done to
address the gap in reporting.  I am in no position to financially
sponsor anyone but certainly the FreeBSD Foundation is.  Maybe someone
from the board could weigh-in regarding the feasibility of funding this
critical function?  According to
<www.freebsdfoundation.org/about/financials/> more than $3M is
available, a small portion of which, if applied on an ongoing basis,
would bring FreeBSD up to the 3rd party application security standards
of its competitors (Android aside) and make the OS infinitely easier for
us to advocate, admin and develop for.

   On that note, does anyone on this list have experience applying for
   FreeBSD Foundation grants?  If so please contact me off-list.

OTOH it may also be a matter of team size and/or policies that would be
more effective in the short term.  Would be great if other sec team and
or board members could comment (ideally without shooting the messenger).

> I do not think the others need to step in for this one, your constant
> negative attitude towards our ports-secteam people is getting annoying and
> a waste of our precious time. So either start sending patches, contribute,
> or understand that this is voluntarily and that their priorities might not
> be your priority.

I don't know Remko.  It seems like too far-reaching of an issue to
ignore.  Most of us don't see it as negative or positive but simply a
means of keeping end-users safe and making everyone's contribution to
the project more effective.

Roger Marquis



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?nycvar.OFS.7.76.444.1812161119470.32121>