Theo de Raadt on OpenSSH security flaws
Posted Mar 29, 2006 15:25 UTC (Wed) by
man_ls (subscriber, #15091)
In reply to:
Theo de Raadt on OpenSSH security flaws by ibukanov
Parent article:
Interview: Theo de Raadt of OpenBSD (NewsForge)
In the interest of responsible disclosure, developers (open or closed) should be notified as soon as you learn about a vulnerability, and the general public some time later. This is what de Raadt does not promise to do.
And it is really a disturbing attitude, given that OpenBSD people are always advocating complete freedom for their source code, even if it means that competitors may take it and release a closed version. Or I should say especially when competitors take it and release a closed version, since these people claim the superiority of their license for this same reason. We must conclude that they do not think closed versions are a bad thing.
(
Log in to post comments)