On quietly fixing security holes
Posted Jul 31, 2003 9:11 UTC (Thu) by
beejaybee (guest, #1581)
Parent article:
On quietly fixing security holes
"With luck, the fix will be widely deployed before anybody notices the problem. If all goes well, many vulnerable installations can be protected before anybody begins to exploit the problem, and without the need for a panic update."
Sounds suspiciously like an excuse for those suppliers who argue for non disclosure.
"crackers do watch changelogs and patch releases, hoping to find just this sort of fix"
Precisely.
I don't think this sort of thing can _ever_ be "ignored". Unpatched systems can and will give linux a bad name if and when a working exploit is developed. IMO every linux user owes a duty to the whole community by keeping systems patched so that exploits cannot get to the point where headlines are likely to be generated.
(
Log in to post comments)