4 ms·
> I bet if the embargo were for 5 days they would reconsider. Here's a page describing the list in question: http://oss-security.openwall.org/wiki/mailing-lis
by SloopJon 12y ago
> I bet if the embargo were for 5 days they would reconsider.
Here's a page describing the list in question:
http://oss-security.openwall.org/wiki/mailing-lists/distros http://oss-security.openwall.org/wiki/mailing-lists/distros
Here's the embargo policy:
> Please note that the maximum acceptable embargo period for issues disclosed to these lists is 14 to 19 days .... In fact, embargo periods shorter than 7 days are preferable.
- alecco 12y ago19 days is an eternity for a security-oriented OS aimed at critical infrastructure like firewalls and proxies.
- paulv 12y ago19 days is nothing compared to how long it has taken non-linux firewall and proxy vendors to patch things in the past.
- numbsafari 12y agoMakes you wonder why people buy those products.
- danudey 12y agoAnd a lot of those vendors just never do. And a lot of users never update anyway. There's no reason to keep my enterprise servers insecure because Johnny Linksys doesn't have a patch that he's never going to install anyway.