On Monday 24 January 2005 19:57, Ciaran McCreesh wrote:

> Those members of the community can go and take it up with VendorSec.
> Most of our users would prefer to get security fixes immediately, rather
> than several months in the future, even if it means having to wait a
> while for the fix information to become public. This is the first time
> anyone's suggested that we leave people with insecure systems rather
> than agree to keep bugs restricted for a while in order to get access to
> vulnerability data sooner.

Right.

>
> Hopefully VendorSec will end up reducing their restriction periods. I'd
> suggest asking them to try to keep the waiting time down rather than
> trying to get rid of limited access bugs altogether, it might get you
> further.

Let's all do that.

Uwe

-- 
Alternative phrasing of the First Law of Thermodynamics:
If you eat it, and you don't burn it off, you'll sit on it.

http://www.uwix.iway.na (last updated: 20.06.2004)

--
[email protected] mailing list

Reply via email to