Date: Sat, 25 Jul 2015 19:41:08 -0500 From: Brad Knowles <brad@...b-internet.org> To: oss-security@...ts.openwall.com Cc: Brad Knowles <brad@...b-internet.org> Subject: Re: Qualys Security Advisory - CVE-2015-3245 userhelper - CVE-2015-3246 libuser On Jul 25, 2015, at 4:55 PM, Dave Horsfall <dave@...sfall.org> wrote: > What would be a reasonable interval (for some definition of "reasonable") > in that case? 24 hours? 48 hours? 0 hours? Any value you choose will be wrong, because there will always be people on both sides of that argument who are violently opposed to any value longer or shorter than what they think is appropriate. Consensus is not only impossible, but these people will actively work to prohibit any possible consensus. Thus begins the flame wars. -- Brad Knowles <brad@...b-internet.org> LinkedIn Profile: <http://tinyurl.com/y8kpxu> Download attachment "signature.asc" of type "application/pgp-signature" (833 bytes)
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Powered by Openwall GNU/*/Linux - Powered by OpenVZ