Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 27 Aug 2001 19:27:59 -0400 (EDT)
From:      Mikhail Kruk <meshko@polkan2.dyndns.org>
To:        Igor Roshchin <str@giganda.komkon.org>
Cc:        "Jacques A. Vidrine" <n@nectar.com>, <freebsd-security@FreeBSD.ORG>, <security-officer@FreeBSD.ORG>
Subject:   Re: procmail, squid: any takers?
Message-ID:  <Pine.BSF.4.33.0108271922360.45703-100000@localhost>
In-Reply-To: <200108272048.f7RKm5k67160@giganda.komkon.org>

next in thread | previous in thread | raw e-mail | index | archive | help
> The main point is that with the trust of the FreeBSD users to the
> FreeBSD core-team and security-officer(s) in particular,
> developed over the years of great work of FreeBSD team,
> people rely [well, maybe sometimes somewhat reluctantly] on the
> FreeBSD advisories, and their timely appearance.

I think anyone who follows advisories for some time knows that they do not
go out immediately after a problem is discovered and usually it even takes
some time after the problem is fixed. I realize that Security Team is
doing what it can, but I think that everyone who subscribes to the list
should be notified that they should not rely on the list as the main
source of security information.

Another possibility (which of course was discussed many times here) is to
release informal warnings on the list as soon as a bug is patched and then
take as long as needed to release formal advisory... I guess it's not a
an acceptable solution for some reason.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.33.0108271922360.45703-100000>