Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 27 Aug 2001 17:44:45 -0700
From:      Kris Kennaway <kris@obsecurity.org>
To:        Christopher Schulte <christopher@schulte.org>
Cc:        Mikhail Kruk <meshko@polkan2.dyndns.org>, Igor Roshchin <str@giganda.komkon.org>, "Jacques A. Vidrine" <n@nectar.com>, freebsd-security@FreeBSD.ORG, security-officer@FreeBSD.ORG
Subject:   Re: procmail, squid: any takers?
Message-ID:  <20010827174445.C48093@xor.obsecurity.org>
In-Reply-To: <5.1.0.14.0.20010827182914.00b00e88@pop.schulte.org>; from christopher@schulte.org on Mon, Aug 27, 2001 at 06:39:54PM -0500
References:  <200108272048.f7RKm5k67160@giganda.komkon.org> <Pine.BSF.4.33.0108271922360.45703-100000@localhost> <5.1.0.14.0.20010827182914.00b00e88@pop.schulte.org>

next in thread | previous in thread | raw e-mail | index | archive | help

--oJ71EGRlYNjSvfq7
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, Aug 27, 2001 at 06:39:54PM -0500, Christopher Schulte wrote:

> My guess is that way too much support would go into 'informal advisories'=
=20
> as people would be clawing the security officer to death asking for exact=
=20
> directions for applying patches and installing fixed binaries.  This is=
=20
> what advisories are for!  Then of course when the security officer made a=
=20
> typo or mistake (which would happen), the same crowd would be right there=
=20
> to point out the mistakes.  Not to mention the madness when we have=20
> differing opinions on how to implement a source fix (remember the telnetd=
=20
> fiasco?).

That's exactly right.  We're not going to start doing "informal
advisories" for the above reasons, but there's no reason the community
couldn't (or in fact shouldn't) be performing this informal support
role themselves.  This already happens to some extent.

People just need to be aware that interim fixes may be wrong (and in
fact the "official fixes" from us may also be wrong, although we of
course strive hard to avoid that case and take responsibility for
correcting the incorrect information when it occurs)

Kris
FreeBSD Security Officer

--oJ71EGRlYNjSvfq7
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (FreeBSD)
Comment: For info see http://www.gnupg.org

iD8DBQE7iul9Wry0BWjoQKURAiNxAKDx6Y9cs5r4nJ+x4t8oPefa9u3dBwCgnNJO
nRm2Fl6wfCI6fV485MBjLvw=
=tFLv
-----END PGP SIGNATURE-----

--oJ71EGRlYNjSvfq7--

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010827174445.C48093>