4 ms·
I see this comment on every discussion regarding OpenBSD and security vulnerability embargoes. Have they stated they won't stick to embargoes or agreed to one a
by naner 8y ago
I see this comment on every discussion regarding OpenBSD and security vulnerability embargoes. Have they stated they won't stick to embargoes or agreed to one and then broke it in the past?
- tedunangst 8y agoFacts don't matter in the narrative zone.
- GavinMcG 8y agoWithout actually answering the question asked or clarifying what you're referring to, your comment is not a good contribution.
- busterarm 8y agotedu is one of the more prolific OpenBSD contributors and has had a front-row seat to the goings-on for a long time. If his experience is that "facts don't matter", literally how can he provide you any kind of contribution that would satisfy you that also doesn't contradict himself? It's an important opinion, without any unnecessary words added.
- GavinMcG 8y agoWell, saying that he's one of the more prolific OpenBSD contributors and has had a front row seat would obviously be a good start...
- deleted 8y ago[deleted]
- beatgammit 8y agoThere's the KRACK vulnerability issue [1] where OpenBSD pushed a minor patch and published information on the originally agreed embargo date, which was extended. OpenBSD made sure to not mention the attack and instead say that it was fixing an OpenBSD-specific issue, and others agreed that it didn't constitute a violation of the embargo agreement. However, given Theo de Raadt's colorful past, OpenBSD's relatively small userbase, and this relatively minor incident, I can see how other companies may think that it's not worth the risk of including OpenBSD in an embargo. It's not fair, but it is what it is. [1] https://marc.info/?l=openbsd-tech&m=152910536208954 https://marc.info/?l=openbsd-tech&m=152910536208954