LWN.net Logo

Trusting free software projects with security information

Trusting free software projects with security information

Posted Jun 27, 2002 12:47 UTC (Thu) by gleef (guest, #1004)
Parent article: Trusting free software projects with security information

If that is the case, then why is their conduct with the OpenSSH vulnerability (where they aparently worked quietly with Theo and other developers) so drastically different than their conduct with Apache?

They messed up with Apache. They should admit it, promise not to do it again, and move on. Making a policy of not notifying Free software project developers is dangerous, particularly when their standard is different for commercial vendors (with no need to keep confidentiality either).


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds