TIP: Click on subject to list as thread! ANSI
echo: nthelp
to: Adam Flinton
from: John Beamish
date: 2004-07-15 11:05:56
subject: Re: July Security patches

From: "John Beamish" 

(I'm not running Linux.)

I find that statement "economical with the truth".  Assume that
you know which module to go to.  Check it out, make the change, check it
in, recompile it, do regression testing (assume the change works and
doesn't break anything), update module documentation, update changelog,
update bugtracking.   In any serious environment, that's a day's work --
not an
hour.

What happens next?  Are Linux users expected to d/l the recompiled module
or is there a process to compare the previous version with the new version
and generate some kind of hex patch which gets downloaded and applied?  Or
what?

Thanks.

"Adam Flinton"  wrote in message

> Security information moves very fast in cracker circles. On the other
> hand, our experience is that coding and releasing of proper security
> fixes typically requires about an hour of work -- very fast fix
> turnaround is possible. Thus we think that full disclosure helps the
> people who really care about security."
>
>
> etc.
>
> Adam

--- BBBS/NT v4.01 Flag-5
* Origin: Barktopia BBS Site http://HarborWebs.com:8081 (1:379/45)
SEEN-BY: 633/267 270
@PATH: 379/45 1 396/45 106/2000 633/267

SOURCE: echomail via fidonet.ozzmosis.com

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.