Openwall GNU/*/Linux - a small security-enhanced Linux distro for servers
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sat, 25 Jul 2015 19:41:08 -0500
From: Brad Knowles <brad@...b-internet.org>
To: oss-security@...ts.openwall.com
Cc: Brad Knowles <brad@...b-internet.org>
Subject: Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser

On Jul 25, 2015, at 4:55 PM, Dave Horsfall <dave@...sfall.org> wrote:

> What would be a reasonable interval (for some definition of "reasonable")
> in that case?  24 hours?  48 hours?  0 hours?

Any value you choose will be wrong, because there will always be people on both sides of that argument who are violently opposed to any value longer or shorter than what they think is appropriate.  Consensus is not only impossible, but these people will actively work to prohibit any possible consensus.

Thus begins the flame wars.

--
Brad Knowles <brad@...b-internet.org>
LinkedIn Profile: <http://tinyurl.com/y8kpxu>


[ CONTENT OF TYPE application/pgp-signature SKIPPED ]

Powered by blists - more mailing lists

Your e-mail address:

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Powered by Openwall GNU/*/Linux - Powered by OpenVZ