On Monday 24 January 2005 19:57, Ciaran McCreesh wrote: > Those members of the community can go and take it up with VendorSec. > Most of our users would prefer to get security fixes immediately, rather > than several months in the future, even if it means having to wait a > while for the fix information to become public. This is the first time > anyone's suggested that we leave people with insecure systems rather > than agree to keep bugs restricted for a while in order to get access to > vulnerability data sooner.
Right. > > Hopefully VendorSec will end up reducing their restriction periods. I'd > suggest asking them to try to keep the waiting time down rather than > trying to get rid of limited access bugs altogether, it might get you > further. Let's all do that. Uwe -- Alternative phrasing of the First Law of Thermodynamics: If you eat it, and you don't burn it off, you'll sit on it. http://www.uwix.iway.na (last updated: 20.06.2004) -- [email protected] mailing list
