|
|
Log in / Subscribe / Register

Security quotes of the week

Security quotes of the week

Posted May 20, 2011 13:18 UTC (Fri) by anselm (subscriber, #2796)
In reply to: Security quotes of the week by jschrod
Parent article: Security quotes of the week

I noted his attitude that he didn't see it necessary to explain *why* it's a bad idea. His style is management-by-appealing-to-authority without backing it with the (existing) facts.

Matt also said that

it's not really cool for project leaders to post their own 0-day 'sploits with vulnerable clients still out there. So not yet.

which I read as an intention to explain the issue in more detail in due course.

I've been following Mercurial development, off and on, for a while (as an interested onlooker, mostly) and I have generally found Matt to be a fairly reasonable person. He could be a lot worse. He could be Dan J. Bernstein or Theo de Raadt :-)


to post comments

Security quotes of the week

Posted May 20, 2011 15:02 UTC (Fri) by jschrod (subscriber, #1646) [Link]

Matt also said that
it's not really cool for project leaders to post their own 0-day 'sploits with vulnerable clients still out there. So not yet.
Well, I didn't understand that, so I ignored it. :-). The OP on the mailing list wanted to revert a change from 2007, so this is not a new introduction but the behavior of hg since 4 years. I didn't understand how there could be a newly introduced vulnerability by a change that didn't get applied.

But then, as I wrote, I don't follow hg development, so there might be some deeper insight that I'm missing. Were it not for XEmacs, I wouldn't even use it. ;-) I wanted to comment on attitude and their appeal, not on security facts. The latter are undisputed.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds