Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 23 Dec 2011 17:57:03 +0100
From:      Damien Fleuriot <ml@my.gd>
To:        Bas Smeelen <b.smeelen@ose.nl>
Cc:        freebsd-stable@freebsd.org
Subject:   Re: FLAME - security advisories on the 23rd ? uncool idea is uncool
Message-ID:  <4EF4B2DF.6000201@my.gd>
In-Reply-To: <20111223165410.5ec6a722@mail.ose.nl>
References:  <20111223165410.5ec6a722@mail.ose.nl>

next in thread | previous in thread | raw e-mail | index | archive | help
On 12/23/11 5:54 PM, Bas Smeelen wrote:
>> Look, just a rant here.
> 
> 
>> Who in *HELL* thought it would be a cool idea to release no less than
>> FOUR security advisories today ?
> What's the impact for your boxes?
> 

Only the BIND exploit concerns me, means that *potentially* servers for
my projects might be unable to run DNS resolution anymore -> prod problems.

I don't think we'll be getting trouble though so I'm postponing the
update until next week.


>> I mean, couldn't this have waited and remained undisclosed until monday ?
> Best time to exploit is Christmas/holidays
> 
>> I for one do *NOT* relish the idea of updating 50+ boxes this evening
>> and tomorrow !
> updating 30 boxes right now
> 
>> Not to mention a whole lot of merchants and banks have toggled IT Freeze
>> a few weeks ago, to ensure xmas shopping doesn't get disturbed by
>> production changes.
> 
> 
>> Seriously, this is just irritating.
> If you don't use telnet, ftpd, dns, pam, then it's not a big problem
> 
> merry Christmas
> 
> Disclaimer: http://www.ose.nl/email
> 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4EF4B2DF.6000201>