4 ms·
Even when the author states that now as a result of that selfishness OpenBSD won't get notified about vulnerabilities until well after everyone else?
by nasduia 9y ago
Even when the author states that now as a result of that selfishness OpenBSD won't get notified about vulnerabilities until well after everyone else?
- cjsuk 9y agoWhat about the vulnerabilities that OpenBSD notice? Works both ways. And they have an active interest in such things and have discovered as much as any famous-for-five-minutes security researcher.
- JumpCrisscross 9y ago> [OpenBSD] have discovered as much as any famous-for-five-minutes security researcher TL; DR OpenBSD acted rationally if they'd prefer to go it alone, which seems to be their culture. To their credit, it's worked pretty well so far. But you can't have your cake and eat it too. If they prefer a mad scramble after public disclosure, they'll get it. But they shouldn't get early notice from responsible researchers.
- cjsuk 9y agoSee my comment here. It sort of replies to this anyway: https://news.ycombinator.com/item?id=15482285 https://news.ycombinator.com/item?id=15482285 I don't believe that embargo is healthy or responsible! If anything its a monopolising factor.
- temprature 9y ago> OpenBSD won't get notified about vulnerabilities until well after everyone else Which doesn't make a difference if OpenBSD still gets their patch out at the same time as everyone else. Unlike other vendors, it doesn't take OpenBSD four months to go from vulnerability notification to patch release, if you look at previous disclosure timelines they typically have a patch out in days.
- abcdef123xyz 9y agoIt sounds rather like he is trying to blame OpenBSD for his own mistake. As multiple people from OpenBSD have said, he agreed they could apply the fix, so they did. He didn't have to say they could. The fact that CERT persuaded him to extend the embargo later is not their fault.